Skip to main content
VerifiedInjection

ShareLeak, where a public form field overrode an enterprise agent's instructions and mailed out customer records

Capsule Security disclosed in April 2026 that text typed into a public facing form field was concatenated straight into a Copilot Studio agent's instructions and overrode them. The agent then queried the connected lists and mailed customer records to an address the attacker chose. Microsoft assigned CVE-2026-21520 and deployed a fix in January 2026.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AIL-2026-0018
Kind
Injection
Jurisdiction
United States
Last verified
Added
  • The research states that the compromised agent accesses connected lists and sends sensitive customer data to an attacker controlled email address.
  • The payload was typed into a public facing form field whose contents were concatenated into the agent's own instruction block.
  • Microsoft assigned CVE-2026-21520 and rated it high, with a fix deployed on 15 January 2026 and disclosure on 15 April 2026.
  • A parallel finding named PipeLeak used a public lead form and an agent's authorized email action against a different vendor's agent platform.
  • The research states that no CVE or public advisory had been issued for the second vendor's finding at the time of publication.

Dimension by dimension

7 dimensions, each one stated, silent or open

Identity, Authorization, Delegation, Limits, Human approval, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

IdentitySilent
Untrusted form text reached the model with the same standing as the operator's own system instructions.Capsule Security, ShareLeak and CVE-2026-21520, primary source, 15 April 2026.
AuthorizationSilent
The agent's connector reach became the attacker's reach the moment the instructions were overridden.Capsule Security, ShareLeak and CVE-2026-21520, primary source, 15 April 2026.
DelegationSilent
No boundary separated processing one submission from querying the whole customer list.Capsule Security, ShareLeak and CVE-2026-21520, primary source, 15 April 2026.
LimitsSilent
Outbound email to an address outside the organisation was permitted, so the exfiltration channel was a normal feature.Capsule Security, ShareLeak and CVE-2026-21520, primary source, 15 April 2026.
Human approvalSilent
The agent sent the message without a person reviewing the recipient.Capsule Security, ShareLeak and CVE-2026-21520, primary source, 15 April 2026.
RevocationStated
One vendor shipped a fix and assigned a CVE; the research records no equivalent for the second platform.Capsule Security, ShareLeak and CVE-2026-21520, primary source, 15 April 2026.
AccountabilityOpen
One vendor named the flaw publicly; the research records that the other did not.Capsule Security, ShareLeak and CVE-2026-21520, primary source, 15 April 2026.

Figures

Every number, with who measured it and when

  1. 7.5 CVSS base score

    CVSS base score assigned to CVE-2026-21520

    Capsule Security, ShareLeak and CVE-2026-21520, primary source, as of .

What it changes

For a team deploying an agent

If a stranger can type into a field your agent reads, that field is part of your prompt. The missing control is limits on the outbound side: an agent that processes public submissions must not be able to send mail to an address outside your directory. Separate the agent that reads untrusted input from the agent that holds connectors, and let only the second one act.

Sources

What this record was verified against

  1. Capsule Security, ShareLeak and CVE-2026-21520Primary · 15 April 2026

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0018 is permanent and is never reused.

In a sentence
According to the GAGE Agent Incident Ledger (as of 15 September 2026), shareleak, where a public form field overrode an enterprise agent's instructions and mailed out customer records.
APA
GAGE (Global Academy of Generative-AI Education). (2026). ShareLeak, where a public form field overrode an enterprise agent's instructions and mailed out customer records. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0018-shareleak-copilot-studio-form-field-took-the-wheel
MLA
"ShareLeak, where a public form field overrode an enterprise agent's instructions and mailed out customer records." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0018-shareleak-copilot-studio-form-field-took-the-wheel.
Chicago
GAGE (Global Academy of Generative-AI Education). "ShareLeak, where a public form field overrode an enterprise agent's instructions and mailed out customer records." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0018-shareleak-copilot-studio-form-field-took-the-wheel.
Permalink
https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0018-shareleak-copilot-studio-form-field-took-the-wheel

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.

Back to the full ledger, or every record for United States and every injection record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.