Analysis of CVE-2026-65669: privilege escalation through SQL Copilot
Attack Techniques & MethodsYesterday, 08:51
Researcher Johann Rehberger disclosed details of CVE-2026-65669 — a critical privilege escalation vulnerability in Copilot for SQL Server Management Studio (SSMS). The issue stems from Copilot executing queries with the privileges of the current SQL connection, while its
read-only mode was enforced by regex-based software validation of queries.The researcher demonstrated that this validation could be bypassed through dynamic invocation of stored procedures: for example, the restriction on
EXEC could be bypassed by storing the procedure name in a variable and then using sp_executesql to execute arbitrary T-SQL. As a result, Copilot could execute CREATE, INSERT, UPDATE, DELETE, DROP and other operations that modify the server state.The researcher also demonstrated an indirect prompt injection: an attacker with fewer privileges placed malicious instructions in database metadata, including through
AGENTS.md or CONSTITUTION.md. When a privileged user accessed the object through Copilot, the instructions entered the model's context and triggered a bypass of read-only, after which arbitrary T-SQL was executed through the victim's connection. In the demonstration, this allowed privileges to be escalated from db_owner to the server role sysadmin.Vulnerabilities
Vendors
Products