Critical server-side vulnerability in Microsoft Copilot Studio allows illegal access to internal infrastructure

A critical vulnerability has been discovered in Microsoft’s Copilot Studio that poses significant risks to sensitive internal data. The flaw, identified as a server-side request forgery (SSRF), allows unauthorized access to internal infrastructure, potentially impacting multiple tenants.

The vulnerability discovered by Tenable’s research team is attributed to improper handling of redirect status codes in user-configurable actions, allowing attackers to manipulate HTTP requests.