Threat reportVulnerabilityTL-2026-0806
SearchLeak: Microsoft 365 Copilot Enterprise One-Click Data Exfiltration (CVE-2026-42824)
SearchLeak: Microsoft 365 Copilot Enterprise One-Click Data (TL-2026-0806), also tracked as SearchLeak, is a critical-severity software vulnerability scored CVSS 7.5, first published 2026-06-15. It has no confirmed attribution, affects Microsoft Microsoft 365 Copilot Enterprise (Copilot Enterprise Search), references 1 CVE (CVE-2026-42824), maps to 15 MITRE ATT&CK techniques (T1027, T1036, T1071), and is covered by 9 detection rules and 16 indicators of compromise.
- CVSS
- 7.5/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 16Indicators of compromise
Key facts for TL-2026-0806
- Threat ID
- TL-2026-0806
- Also known as
- SearchLeak
- Severity
- CRITICAL
- CVSS
- 7.5
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- enterprise
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in SearchLeak: Microsoft 365 Copilot Enterprise One-Click Data
Malware and tooling: SearchLeak proof-of-concept (Varonis Threat Labs)
How SearchLeak: Microsoft 365 Copilot Enterprise One-Click Data works
SearchLeak is a one-click data-exfiltration vulnerability chain in Microsoft 365 Copilot Enterprise Search discovered by Varonis Threat Labs. It chains parameter-to-prompt injection via the 'q' URL parameter, an HTML rendering race condition during Copilot's response streaming that fires attacker <img> tags before sanitization wraps output in <code> blocks, and a Content-Security-Policy bypass via server-side request forgery (SSRF) through Bing's allowlisted 'Search by Image' endpoint to leak mailbox contents, MFA/one-time codes, calendar data, and SharePoint/OneDrive files. Microsoft assigned CVE-2026-42824, rated it Critical, and fully mitigated it server-side; only a proof-of-concept was demonstrated, with no observed in-the-wild exploitation.
SearchLeak (CVE-2026-42824) is a three-stage exploit chain against Microsoft 365 Copilot Enterprise Search demonstrated by Varonis Threat Labs researcher Dolev Taler. Individually the three bugs are insufficient for a meaningful attack; chained together they enable single-click theft of any data the victim's Copilot can reach through inherited Microsoft Graph access.
Stage 1 — Parameter-to-prompt injection: The Copilot Enterprise Search URL exposes a 'q' parameter intended for search terms. Copilot reads whatever sits in 'q' as instructions rather than a literal query, so an attacker crafts a link instructing Copilot to search the victim's mailbox (or other data sources), extract values such as email subjects or one-time codes, and embed them in an image URL — all without the victim typing anything. Because the crafted link points to a legitimate microsoft.com domain, traditional anti-phishing and URL-filtering tools are unlikely to flag it.
Stage 2 — HTML rendering race condition: As a guardrail, Microsoft wraps dangerous Copilot-generated HTML inside <code> blocks so markup is not interpreted. The wrapping, however, only happens after Copilot finishes generating, while the browser renders the response stream as it arrives. During this streaming window the raw HTML — including an attacker-injected <img> tag — is temporarily live in the DOM and the browser issues the image request before sanitization neutralizes it.
Stage 3 — CSP bypass via Bing SSRF: Copilot's Content-Security-Policy blocks direct attacker-controlled connections, but allowlists *.bing.com. Bing's 'Search by Image' feature accepts an image URL parameter and performs a server-side fetch of that URL. The attacker points this feature at their own server with the stolen data encoded in the URL. Because the outbound request originates from Bing's infrastructure rather than the browser, CSP never applies, and Bing acts as an unwitting exfiltration proxy. The attacker reads the stolen data from their own server logs.
The full flow: the victim clicks the crafted Copilot Search link; Copilot searches the victim's data; the streamed response embeds a value such as an email subject in a Bing image URL; the browser calls Bing during streaming; Bing fetches the attacker's URL carrying the stolen data. Exfiltratable data includes email content (including access codes and passwords), one-time/MFA codes enabling rapid account takeover, calendar events and meeting notes, and SharePoint/OneDrive files indexed by Copilot Enterprise Search.
SearchLeak belongs to a recurring AI-assistant bug class: Varonis' earlier Reprompt attack used the same one-click technique against Copilot Personal and held up against Enterprise Search despite its extra guardrails, and Aim Labs' 2025 EchoLeak (CVE-2025-32711) was a zero-click variant. As the researchers note, SSRF and sanitizer races are old bug classes — the prompt injection is the new part. Microsoft assigned CVE-2026-42824 with a Critical (maximum) severity rating, CVSS 6.5 by Microsoft and 7.5 by NVD, and fully mitigated the flaw server-side in early June 2026; because Copilot Enterprise is a managed service, tenant administrators cannot patch the components themselves and no customer action is required.
MITRE ATT&CK techniques used in TL-2026-0806
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
Command and Control
T1071 Application Layer Protocol; T1102 Web Service
Credential Access
T1111 Multi-Factor Authentication Interception; T1552 Unsecured Credentials
Collection
T1114 Email Collection; T1213 Data from Information Repositories; T1530 Data from Cloud Storage
Initial Access
T1190 Exploit Public-Facing Application; T1566 Phishing
Execution
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
Affected products and versions in SearchLeak: Microsoft 365 Copilot Enterprise One-Click Data
- Microsoft — Microsoft 365 Copilot Enterprise (Copilot Enterprise Search)
Vulnerable versions: Cloud service prior to early-June 2026 server-side fix
Fixed in: Server-side mitigation deployed early June 2026
Remediation for SearchLeak: Microsoft 365 Copilot Enterprise One-Click Data
Patches
- Microsoft server-side mitigation deployed early June 2026 (managed service; no tenant-side patch to apply)
Immediate actions
- No customer action required: Microsoft mitigated SearchLeak server-side in early June 2026 for all Copilot Enterprise tenants
- Monitor Copilot Enterprise Search URLs for encoded payloads, HTML, or <img> tags in the 'q' parameter
- Alert users to inspect Microsoft 365 links carrying long encoded query strings before clicking, even on legitimate microsoft.com domains
Workarounds
- Disable or restrict Copilot Enterprise Search where business need does not justify the exposure (pre-patch mitigation)
Longer-term hardening
- Treat AI streaming output as untrusted and sanitize at render time, not only after generation completes
- Audit CSP allowlists for any domain (e.g. *.bing.com) that performs server-side fetches of user-supplied URLs and can act as an SSRF/exfiltration proxy
- Restrict Copilot indexing scope and apply least-privilege to Microsoft Graph data sources to minimize blast radius of future Copilot data-leak bugs
- Detect unusual outbound requests to Bing image-search endpoints correlated with Copilot sessions
CVEs associated with SearchLeak: Microsoft 365 Copilot Enterprise One-Click Data
Weaknesses (CWE) in SearchLeak: Microsoft 365 Copilot Enterprise One-Click Data
Timeline of SearchLeak: Microsoft 365 Copilot Enterprise One-Click Data
- EchoLeak (CVE-2025-32711), a zero-click Microsoft 365 Copilot data-leak vulnerability by Aim Labs combining indirect prompt injection, markdown-image exfiltration and CSP bypass, established the bug class SearchLeak later builds on.
- Varonis researcher Dolev Taler demonstrated the Reprompt one-click data-theft technique against Microsoft Copilot Personal, the precursor technique that held up against Copilot Enterprise Search.
- Microsoft assigned CVE-2026-42824 (M365 Copilot Information Disclosure) and rated it Critical / maximum severity; CVSS 6.5 (Microsoft) and 7.5 (NVD).
- Microsoft mitigated SearchLeak server-side in early June 2026 across Copilot Enterprise tenants; as a managed service, no customer action was required.
- SearchLeak landed amid a broader June 2026 cluster of Microsoft Copilot information-disclosure fixes, including CVE-2026-47644 (Copilot Chat information disclosure affecting Microsoft Edge), reflecting a recurring AI-assistant data-leak bug class.
- Coverage highlighted a CVSS scoring disagreement for CVE-2026-42824 — Microsoft scored it 6.5 while NVD scored it 7.5 — even though Microsoft assigned a Critical / maximum severity rating; NVD classified the root cause as command injection (CWE-77).
- BleepingComputer, The Hacker News and Cyber Security News reported the SearchLeak chain (prompt injection + HTML streaming race condition + Bing SSRF/CSP bypass).
- Varonis Threat Labs publicly disclosed SearchLeak with a proof-of-concept; no in-the-wild exploitation was observed.
Sources cited for SearchLeak: Microsoft 365 Copilot Enterprise One-Click Data
- Microsoft 365 Copilot One-Click Vulnerability (SearchLeak)
- New attack turned Microsoft 365 Copilot into 1-click data theft tool
- One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
- CVE-2026-42824 - M365 Copilot Information Disclosure Vulnerability (MSRC Security Update Guide)
- EchoLeak in Microsoft Copilot: What it Means for AI Security (CVE-2025-32711)
- Reprompt: The Single-Click Microsoft Copilot Attack that Silently Steals Your Personal Data
- Microsoft 365 Copilot Security Coverage
- CVE-2026-42824 Information Disclosure Risk and AI Security Checklist
- Microsoft fixes critical Copilot information disclosure vulnerabilities
- CVE-2026-47644: Copilot Chat Information Disclosure Vulnerability Hits Microsoft Edge
Detection coverage for TL-2026-0806
As of 2026-06-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0806 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.