CVE-2024-38206: Microsoft Copilot Studio

Medium severity, CVSS 6.5. EPSS: 12.3% chance of exploitation in the next 30 days.

An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network.

Affected products

  • Microsoft Copilot Studio: affected versions not specified

Published 2024-08-06. Last modified 2026-06-17.