ShareLeak, where a public form field overrode an enterprise agent's instructions and mailed out customer records
Capsule Security disclosed in April 2026 that text typed into a public facing form field was concatenated straight into a Copilot Studio agent's instructions and overrode them. The agent then queried the connected lists and mailed customer records to an address the attacker chose. Microsoft assigned CVE-2026-21520 and deployed a fix in January 2026.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AIL-2026-0018
- Kind
- Injection
- Jurisdiction
- United States
- Last verified
- Added
- The research states that the compromised agent accesses connected lists and sends sensitive customer data to an attacker controlled email address.
- The payload was typed into a public facing form field whose contents were concatenated into the agent's own instruction block.
- Microsoft assigned CVE-2026-21520 and rated it high, with a fix deployed on 15 January 2026 and disclosure on 15 April 2026.
- A parallel finding named PipeLeak used a public lead form and an agent's authorized email action against a different vendor's agent platform.
- The research states that no CVE or public advisory had been issued for the second vendor's finding at the time of publication.
Dimension by dimension
7 dimensions, each one stated, silent or open
Identity, Authorization, Delegation, Limits, Human approval, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentitySilent
- Untrusted form text reached the model with the same standing as the operator's own system instructions.Capsule Security, ShareLeak and CVE-2026-21520, primary source, 15 April 2026.
- AuthorizationSilent
- The agent's connector reach became the attacker's reach the moment the instructions were overridden.Capsule Security, ShareLeak and CVE-2026-21520, primary source, 15 April 2026.
- DelegationSilent
- No boundary separated processing one submission from querying the whole customer list.Capsule Security, ShareLeak and CVE-2026-21520, primary source, 15 April 2026.
- LimitsSilent
- Outbound email to an address outside the organisation was permitted, so the exfiltration channel was a normal feature.Capsule Security, ShareLeak and CVE-2026-21520, primary source, 15 April 2026.
- Human approvalSilent
- The agent sent the message without a person reviewing the recipient.Capsule Security, ShareLeak and CVE-2026-21520, primary source, 15 April 2026.
- RevocationStated
- One vendor shipped a fix and assigned a CVE; the research records no equivalent for the second platform.Capsule Security, ShareLeak and CVE-2026-21520, primary source, 15 April 2026.
- AccountabilityOpen
- One vendor named the flaw publicly; the research records that the other did not.Capsule Security, ShareLeak and CVE-2026-21520, primary source, 15 April 2026.
Figures
Every number, with who measured it and when
- 7.5 CVSS base score
CVSS base score assigned to CVE-2026-21520
Capsule Security, ShareLeak and CVE-2026-21520, primary source, as of .
What it changes
For a team deploying an agent
If a stranger can type into a field your agent reads, that field is part of your prompt. The missing control is limits on the outbound side: an agent that processes public submissions must not be able to send mail to an address outside your directory. Separate the agent that reads untrusted input from the agent that holds connectors, and let only the second one act.
Sources
What this record was verified against
- Capsule Security, ShareLeak and CVE-2026-21520Primary · 15 April 2026
Related
Records that sit beside this one
ForcedLeak, a lead form that turned a CRM agent into an exfiltration path through an expired allowlisted domain
United States · verified 15 September 2026
Noma Security states that an allowlisted domain had expired and become available for purchase, and that the researchers bought it.
EchoLeak, a zero click chain that pulled tenant data out of Microsoft 365 Copilot
United States · verified 15 September 2026
Microsoft's advisory for CVE-2025-32711 states the vulnerability has already been fully mitigated and that there is no action for users of the service to take.
A support agent invented a policy its company did not have, and customers cancelled over it
United States · verified 15 September 2026
A company representative stated publicly that there is no such policy and that users are free to use the product on multiple machines.
A vendor's own red team made a browser agent send a resignation letter for the user, then showed the fixed agent refusing
United States · verified 15 September 2026
The vendor's own account states that the out of office reply never gets written and the agent resigns on behalf of the user instead.
A browser agent read the local file system and shipped it out while still answering the user normally
United States · verified 15 September 2026
The research states the agent autonomously accesses the local file system and exfiltrates the contents to an attacker controlled endpoint while still returning the expected response.
GitLost, where a platform's own workflow agent posted private repository contents into a public issue when asked politely
United States · verified 15 September 2026
The Register reports that the attacker hides the commands in plain English in the issue body and the agent then posts the data as a public comment.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0018 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), shareleak, where a public form field overrode an enterprise agent's instructions and mailed out customer records.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). ShareLeak, where a public form field overrode an enterprise agent's instructions and mailed out customer records. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0018-shareleak-copilot-studio-form-field-took-the-wheel
- MLA
- "ShareLeak, where a public form field overrode an enterprise agent's instructions and mailed out customer records." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0018-shareleak-copilot-studio-form-field-took-the-wheel.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "ShareLeak, where a public form field overrode an enterprise agent's instructions and mailed out customer records." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0018-shareleak-copilot-studio-form-field-took-the-wheel.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0018-shareleak-copilot-studio-form-field-took-the-wheel
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger, or every record for United States and every injection record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.