Microsoft 365 Copilot Flaw: How Attackers Could Steal Your Data with One Click (2026)

In the ever-evolving landscape of cybersecurity, where threats are becoming increasingly sophisticated, a recent discovery by researchers at Varonis Threat Labs has exposed a critical vulnerability in Microsoft 365 Copilot Enterprise Search. This flaw, dubbed SearchLeak, highlights the potential for a single click on a trusted Microsoft link to expose sensitive data, including emails, calendar details, and indexed files. What makes this particularly fascinating is the intricate interplay of three distinct bugs, each contributing to a one-click exfiltration path that traditional security measures might fail to detect. This incident underscores the importance of staying vigilant and adapting to the evolving tactics of cybercriminals.

The Three Bugs, One Click Exfiltration Path

At the heart of SearchLeak is a command injection vulnerability that can expose information over a network. This vulnerability is not a standalone issue but rather a combination of two old web bugs and an AI-specific weakness. The entry point is the q parameter in the Copilot Enterprise Search URL, which is designed for natural-language queries but can be manipulated by attackers. By crafting a URL that tells Copilot to search the mailbox and extract email titles, attackers can bypass the need for user input, making the attack even more insidious.

What makes this attack particularly effective is the race condition in how the response renders. Microsoft's guardrail wraps Copilot output in code blocks to ensure the browser treats markup as text. However, the timing of this wrapping is crucial. The injected tag is drawn and fires its request before the sanitizer runs, allowing the request to leave before the output is neutralized. This race condition, combined with a Content Security Policy (CSP) allowlist, enables attackers to exfiltrate data through Bing's infrastructure, making it a powerful tool for data theft.

The Data at Stake

The implications of this vulnerability are far-reaching. Copilot Enterprise can access whatever the signed-in user can through their Microsoft Graph access, and attackers can inherit this reach without logging in. The most time-sensitive data, such as one-time codes, MFA codes, and password-reset links, is particularly vulnerable. A script that lifts this data off a log while the window is open can take over an account before anyone notices. Additionally, the same access grants attackers access to calendar invites, meeting notes, and any SharePoint or OneDrive files Copilot has indexed, including sensitive information like salary data, earnings figures, and acquisition plans.

A Pattern of Vulnerabilities

This is not the first time Varonis has uncovered such a pattern. In an earlier Reprompt attack against Copilot Personal, researchers demonstrated a similar one-click technique. This attack, which held up against Copilot Enterprise Search despite the additional guardrails, highlights the persistence of this vulnerability across different versions of Copilot. Furthermore, the same pattern was observed in EchoLeak, a zero-click Copilot data-leak bug disclosed in 2025, further emphasizing the need for vigilance and proactive security measures.

Mitigation and Containment

Microsoft has mitigated the flaw on its backend, and because Copilot Enterprise is a managed service, tenant admins cannot patch or reconfigure the failed parts. However, they can take steps to contain the threat. Admins should look for Copilot Search URLs carrying encoded payloads or HTML in the q parameter and for unusual outbound requests to Bing's image endpoints. Tightening data-access governance so Copilot indexes less can also reduce the scope of any future leak.

The Broader Implications

This incident raises deeper questions about the balance between innovation and security. As AI-powered tools like Copilot become more integrated into our digital lives, the potential for misuse and exploitation increases. It is crucial to strike a balance between embracing new technologies and ensuring they are secure and reliable. The vulnerability in Copilot Enterprise Search serves as a reminder that even trusted tools can have hidden weaknesses, and staying informed and proactive is essential in the face of evolving cyber threats.

In conclusion, the SearchLeak vulnerability in Microsoft 365 Copilot Enterprise Search is a stark reminder of the importance of cybersecurity in the digital age. As we continue to innovate and adopt new technologies, we must also ensure that they are secure and reliable. By staying informed and proactive, we can mitigate the risks and protect our data and systems from malicious actors.

Microsoft 365 Copilot Flaw: How Attackers Could Steal Your Data with One Click (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Rev. Leonie Wyman

Last Updated:

Views: 6411

Rating: 4.9 / 5 (79 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Rev. Leonie Wyman

Birthday: 1993-07-01

Address: Suite 763 6272 Lang Bypass, New Xochitlport, VT 72704-3308

Phone: +22014484519944

Job: Banking Officer

Hobby: Sailing, Gaming, Basketball, Calligraphy, Mycology, Astronomy, Juggling

Introduction: My name is Rev. Leonie Wyman, I am a colorful, tasty, splendid, fair, witty, gorgeous, splendid person who loves writing and wants to share my knowledge and understanding with you.