Copilot and LiteLLM both shattered the same AI trust boundary in 2 weeks
Varonis tied SearchLeak (CVE-2026-42824) and Obsidian mapped LiteLLM chains, turning “shadow AI” into board-level risk.

Varonis disclosed SearchLeak (CVE-2026-42824) against Microsoft 365 Copilot Enterprise Search on June 15, and Obsidian Security published a three-CVE chain against LiteLLM four days earlier. Together, the disclosures show how AI tools can accept external input without a real trust boundary, creating exploitable data and credential paths.
Two weeks. Two AI products. Same failure mode: an AI tool accepts external input and the organization never draws an actual trust boundary. On June 15, Varonis disclosed SearchLeak (CVE-2026-42824), a proof-of-concept exfiltration chain in Microsoft 365 Copilot Enterprise Search. The attack starts with a victim clicking a crafted microsoft.com URL, Copilot searching their mailbox, and the data leaving through a Bing SSRF. Microsoft rated the flaw critical and patched it on the back end, according to Varonis; NVD has not yet scored it, while a third-party tracker lists it at 6.5 medium.
Four days earlier, Obsidian Security published a three-CVE chain that turned LiteLLM from a gateway into a privilege escalation and remote code execution path. The escalation runs from a non-admin to proxy admin, then escapes the code sandbox through exec() with full builtins. Obsidian also demonstrated a reverse shell by injecting a forged tool-call response through LiteLLM’s callback mechanism, and assessed the combined chain at CVSS 9.9. One pattern, two tools, and the shared lesson is blunt: enterprise AI can inherit permissions, then leak them, if the “boundary” is more promise than policy.
The operational takeaway is why this keeps landing in enterprise environments that think they are safe. SearchLeak chained three weaknesses into a silent data-theft chain: the URL q parameter fed attacker instructions directly to Copilot’s LLM; a rendering race condition fired an image tag before output sanitization ran; and Bing’s image-search endpoint, allowlisted in Content Security Policy, routed the stolen data out. There were no plugins and no second click, and Varonis describes it as “one-click mailbox exfiltration.” The severity is contested in scoring (critical by Microsoft, not yet scored by NVD, 6.5 medium by a third-party tracker), but the mechanism is the point: input gets transformed into actions that bypass what the organization assumed would stop leakage.
LiteLLM’s chain is a different bug class, but the same trust boundary gap. The LiteLLM gateway holds keys for OpenAI, Anthropic, Azure, and Bedrock behind a single proxy, which means if the gateway identity and authorization checks fail, the organization’s provider credentials can be exposed. Obsidian’s three-step escalation starts with CVE-2026-47101, an authorization bypass that lets a non-admin mint a wildcard API key. Then CVE-2026-47102 promotes that caller to proxy admin through an unguarded /user/update endpoint. Finally, CVE-2026-40217 escapes the code sandbox via exec() with full builtins. Obsidian’s reverse shell demonstration used LiteLLM’s callback mechanism, injecting a forged tool-call response. In other words, the system doesn’t just mis-handle one request; it lets an attacker manufacture the authority to act, then uses that authority to run code.
This is not the first time Varonis has flagged Copilot exfiltration chains: SearchLeak is the third Varonis Copilot exfiltration chain in twelve months, after Reprompt in January and EchoLeak in 2025. The earlier ones targeted Copilot Personal and then Search, but the inheritance point is the same. Enterprise Search inherits the user’s full organizational permissions, so the blast radius becomes everything the user can reach. The source also notes a separate LiteLLM flaw, CVE-2026-42271, a command-injection bug in the MCP test endpoints, which landed on the CISA KEV list on June 8 with a June 22 remediation deadline. That KEV item is distinct from the Obsidian authorization and RCE chain, but it underscores the same theme: when you have a shared gateway, weaknesses stack.
And it is bigger than Copilot and LiteLLM. The same trust boundary break hit Langflow (CVE-2026-5027), where a path traversal in file upload can allow writing files anywhere on disk, and auto-login enabled by default can turn an unauthenticated request into remote code execution. VulnCheck confirmed exploitation on June 9, and Censys counted roughly 7,000 exposed instances, concentrated most in North America, attributed to MuddyWater. Meanwhile, the Mini Shai-Hulud campaign targeted a different layer: after the worm’s source code went public on May 12, copycat variants compromised 32 Red Hat Cloud Services npm packages on June 1, with packages pulled 80,000 times a week. That worm harvests more than 20 credential types and self-propagates under the compromised maintainer’s identity. Different mechanics, same boundary gap.
So what should executives and boards do with this? First, the industry’s AI risk is now running at the pace of patching and governance, not the pace of zero-day mythmaking. CrowdStrike’s AIDR grew ending ARR more than 250% sequentially in Q1 FY27, with a Q2 pipeline above $50 million (SEC-filed 8-K), and its total company ARR reached $5.51 billion. CrowdStrike also reports more than 1,800 agentic applications running across enterprise endpoints. The company’s Daniel Bernard said the AI attack surface now spans development, runtime, identities, and cloud infrastructure, and that teams treating those as separate domains leave gaps between them open. David Levin, CISO at American Express Global Business Travel, framed it as “shadow AI,” the new version of shadow IT, and pushed for fundamentals before deployment, pointing to NIST and OWASP. Merritt Baer, CSO at Enkrypt AI and former AWS Deputy CISO, described the deeper structural issue: organizations approve an interface, not the underlying system, and “composability is” where the risk lives. Adam Meyers, CrowdStrike’s SVP of Intelligence, added the operational squeeze: “The problem is not zero-day. The problem is patching.” If you 10x that problem, teams can be underwater.
The strategic stakes for every peer are simple. This isn’t one exotic exploit category. It is an operating failure where AI gateways and agent identities bridge model output to real data, real permissions, and real code. When those bridges are governed late, or not at all, the attacker does not need custom malware. They need an input channel and a place where trust is assumed. Fixing the next patch matters. Fixing the trust boundary matters more.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Business

Anthropic’s Levant Alpöge cracks the Jacobian conjecture after 87 years
A Harvard valedictorian used Claude to hit a 1939 breakthrough, but the missing “why” is the real problem.

Uber buys Delivery Hero for nearly $15B, vaulting to top food delivery outside China
The deal doubles Uber's dual-services footprint and pushes a ride-and-eats bundling play into 50 more markets.

Epic and Google drop settlement bid, forcing rival Android app stores by July 22
Google told the court it is ready to carry third-party app stores starting Wednesday, July 22.
