Microsoft Copilot searches mail. SearchLeak leaks it through Bing SSRF, patched by June 15
A one-click mailbox exfiltration chain in CVE-2026-42824 plus a LiteLLM admin-key escalation you should audit Monday.

Varonis disclosed SearchLeak (CVE-2026-42824), a proof-of-concept exfiltration chain in Microsoft 365 Copilot Enterprise Search disclosed June 15. Separate research shows LiteLLM can hand out admin keys to default provider access, and the same trust-boundary failure shows up across tools.
Microsoft 365 Copilot Enterprise Search can turn a crafted microsoft.com URL into one-click mailbox exfiltration. Varonis disclosed that chain as SearchLeak (CVE-2026-42824) on June 15: a victim clicks the URL, Copilot searches their mailbox, and the data leaves through a Bing SSRF. Microsoft rated the flaw critical and patched it on the back end, according to Varonis, but the key operational point is simpler than the mechanics: if the boundary between “external input” and “what the AI can access” is fuzzy, data theft stops looking exotic.
Four days earlier, Obsidian Security published a three-CVE escalation chain against LiteLLM that carried a default low-privilege user all the way to admin and remote code execution. The combined story is the same across both disclosures: enterprise AI accepts external input with no trust boundary. And the board-level consequence is immediate, not theoretical. Enterprise Search inherits the user’s full organizational permissions, so “a single crafted click” can become “everything your user can reach.”
To make this actionable, the five-check audit maps each trust-boundary gap to what broke, how to verify on Monday, the fix, and board-ready language. Start with the most obvious failure class: prompt-to-data search. In SearchLeak, the URL q parameter feeds attacker instructions straight to Copilot’s LLM. Then a rendering race condition fires an image tag before the output sanitizer runs. Finally, a Bing’s image-search endpoint that is allowlisted in the Content Security Policy routes the stolen data out. Varonis’ disclosure frames it as a chain with no plugins, no second click, and no visible indicator. NVD has not yet scored it, and a third-party tracker lists it at 6.5 medium, but severity is almost the wrong debate here. The mechanism is the point: escalation of attacker-controlled text into attacker-controlled access.
Now zoom out to LiteLLM, because it is the “admin keys” headline in this roundup. LiteLLM is a gateway that holds the keys for OpenAI, Anthropic, Azure, and Bedrock behind a single proxy. The Obsidian chain runs in three moves. CVE-2026-47101 is an authorization bypass that lets a non-admin mint a wildcard API key. CVE-2026-47102 promotes that caller to proxy admin through an unguarded /user/update endpoint. CVE-2026-40217 escapes the code sandbox through exec() with full builtins. Obsidian also demonstrated a reverse shell by injecting a forged tool-call response through LiteLLM’s callback mechanism. Obsidian assessed the combined chain at CVSS 9.9. Separately, CVE-2026-42271, a command-injection bug in the MCP test endpoints, landed on the CISA KEV list on June 8 with a June 22 remediation deadline, and this KEV entry is distinct from the Obsidian chain. The shared theme is still the same: an “interface” that is treated like a control plane, when it actually behaves like an attack surface.
This is not the first time Varonis has had to describe Copilot exfiltration chains. The disclosure notes SearchLeak as the third Varonis Copilot exfiltration chain in twelve months, after Reprompt in January and EchoLeak in 2025. And enterprise scope matters for the same reason it always does in security: Enterprise Search inherits the user’s full organizational permissions, meaning blast radius follows identity. The audit should therefore treat “who the AI runs as” as a first-class security object, not an implementation detail.
Supply-chain risk makes the boundary problem worse, not better. The source notes a supply-chain compromise backdoored LiteLLM versions 1.82.7 and 1.82.8 on PyPI in March. A compromised gateway exposes every provider credential the organization holds. And Langflow and Mini Shai-Hulud show how quickly copyable patterns turn into systemic incidents. Langflow CVE-2026-5027 became the third Langflow remote-code-execution flaw to hit active exploitation this year, where a path traversal in file upload lets an attacker write files anywhere on disk, and auto-login enabled by default allows an unauthenticated request to reach RCE. VulnCheck confirmed exploitation on June 9. Censys counted roughly 7,000 exposed instances, with the heaviest concentration in North America, and MuddyWater attribution. Mini Shai-Hulud is described as a worm that, after the worm’s source code went public on May 12, compromised 32 Red Hat Cloud Services npm packages on June 1. Those packages were pulled 80,000 times a week. The worm harvests more than 20 credential types and self-propagates under the compromised maintainer’s identity.
Meanwhile, the market is pricing the “AI attack surface” expansion as a real spend category. CrowdStrike’s Q1 FY27 earnings call put a number on the gap: AIDR, the company’s AI detection and response line, grew ending ARR more than 250% sequentially, with a Q2 pipeline above $50 million (SEC-filed 8-K). Total company ARR reached $5.51 billion, and CrowdStrike’s fleet telemetry shows more than 1,800 agentic applications running across enterprise endpoints. On June 17, CrowdStrike extended AIDR to AWS, adding real-time evaluation of agent, LLM, and MCP communications across Amazon Bedrock, Kiro, and Strands Agents, building on its work with Anthropic’s Project Glasswing. Daniel Bernard, CrowdStrike’s chief business officer, said the AI attack surface now spans development, runtime, identities, and cloud infrastructure, and that teams treating those as separate domains leave gaps between them open.
David Levin, CISO at American Express Global Business Travel, told VentureBeat the pattern does not surprise him. “We kind of have this shadow AI, which is just the new version of shadow IT,” Levin said. He frames the fix as fundamentals before deployment, pointing to NIST CSF and NIST AI framework, plus OWASP’s top 10. Merritt Baer, CSO at Enkrypt AI and former AWS Deputy CISO, said enterprises believe they have approved AI vendors, but have approved an interface, not the underlying system. “The real dependencies are one or two layers deeper,” she said. Her core risk framing is that composability is where compromise lives. Adam Meyers, CrowdStrike’s SVP of Intelligence, put the operational squeeze in plain terms: “The problem is not zero-day. The problem is patching. If you 10x that problem, they’re gonna be completely underwater,” he said, then added identity as the second front.
So what is the strategic stake for executives who manage risk like it is a product roadmap? SearchLeak shows how one crafted external input can cascade into data theft when the boundary between prompt and permissions is missing. LiteLLM shows how a gateway that holds provider keys can turn a default account into admin and then into execution. Langflow and Mini Shai-Hulud show the pattern scales when teams treat AI tooling as an add-on instead of a governed system. The five-check audit exists because the board does not need another “AI is risky” slide deck. It needs a Monday command, a mapped proof point, and a shared sentence that makes the boundary failure obvious enough to fund.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Business

Anthropic’s Levant Alpöge cracks the Jacobian conjecture after 87 years
A Harvard valedictorian used Claude to hit a 1939 breakthrough, but the missing “why” is the real problem.

Uber buys Delivery Hero for nearly $15B, vaulting to top food delivery outside China
The deal doubles Uber's dual-services footprint and pushes a ride-and-eats bundling play into 50 more markets.

Epic and Google drop settlement bid, forcing rival Android app stores by July 22
Google told the court it is ready to carry third-party app stores starting Wednesday, July 22.

