Signature Verification Flaw Allows Privilege Escalation in Microsoft Copilot Studio
AI analysis
Microsoft Copilot Studio, the low-code cloud service in the Power Platform used to build AI copilots and agents, fails to properly verify cryptographic signatures on certain network traffic (CWE-347), allowing signature checks to be bypassed. An unauthenticated attacker can trigger the flaw remotely over a network with no user interaction by sending a crafted request whose signature is accepted without correct verification. Successful exploitation elevates the attacker's privileges, and the changed-scope CVSS metric plus high confidentiality, integrity, and availability ratings indicate impact that extends beyond the immediate component. Because Copilot Studio is a multi-tenant Microsoft-hosted service, every organization using the service falls within the blast radius, and there are no on-premises versions to inventory. As of the September 2026 Patch Tuesday disclosure, no in-the-wild exploitation is known, there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a modest 0.3% probability of exploitation within 30 days.
What to do: Because Copilot Studio is a Microsoft-managed SaaS offering, there is no customer-side patch to install; verify via the Microsoft 365 admin center (message center and service health) that the September 2026 service update has been applied to your tenant. In the meantime, review tenant audit logs for anomalous privilege changes or unexpected agent activity, and scrutinize the permissions and authentication settings of any agents exposed to unauthenticated users. Follow Microsoft's advisory for the CVE in case compensating controls or configuration guidance are provided.
Affected
| microsoft copilot studio | — |
Estimated exposure
masslikely millions of users across on the order of 100,000+ organizations (multi-tenant Microsoft 365/Power Platform SaaS with no per-install counts) — Copilot Studio is a centrally hosted Microsoft cloud service whose adoption Microsoft has publicly put in the hundreds of thousands of organizations, so exposure applies at the service/tenant level rather than to discrete on-premises…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.