Score breakdown
Popularity is tracked separately. Support, ads, sponsorships, and tips never affect these signals.
Why it matters
Useful for security teams and AI-app builders: the underlying technique (P2P injection chained with cross-service SSRF) generalizes to any AI assistant that combines retrieval with outbound rendering. Audit M365 Copilot query logs and consider restricting access to sensitive libraries until mitigations ship.
Who should use it
Who should skip it
Skip Microsoft 365 Copilot 'SearchLeak' data-theft chain (CVE-2026-26137) for now if you are only tracking items with a 'try now' verdict.
About this signal
Microsoft 365 Copilot 'SearchLeak' data-theft chain (CVE-2026-26137) is tracked by RepoRadar as a signal in the Radar section. First seen 2026-06-16; the source record was last checked on 2026-06-16. The current verdict is 'watch' with a Gold tier and review needed setup difficulty. Across RepoRadar's eight signals, Microsoft 365 Copilot 'SearchLeak' data-theft chain (CVE-2026-26137) is strongest on practical usefulness (8.0) and workflow potential (8.0) and weakest on evidence quality (5.8) — a profile worth weighing against your own priorities. This page summarizes the public evidence on the linked source page and states where additional review is still needed.
How this item is evaluated
The Microsoft 365 Copilot 'SearchLeak' data-theft chain (CVE-2026-26137) record combines a 8.0/10 composite score with separate popularity (65.0), risk (none), and setup (review needed) signals. See the scoring methodology for the current weights and evidence definitions.
Putting this into practice? Read How to evaluate an AI tool before you adopt it for the checklist behind this score.
Risk explanation
No inherent user-impacting risk is flagged from the captured evidence.