Analysis of CVE-2026-65669: privilege escalation through SQL Copilot

Researcher Johann Rehberger disclosed details of CVE-2026-65669 — a critical privilege escalation vulnerability in Copilot for SQL Server Management Studio (SSMS). The issue stems from Copilot executing queries with the privileges of the current SQL connection, while its read-only mode was enforced by regex-based software validation of queries.
The researcher demonstrated that this validation could be bypassed through dynamic invocation of stored procedures: for example, the restriction on EXEC could be bypassed by storing the procedure name in a variable and then using sp_executesql to execute arbitrary T-SQL. As a result, Copilot could execute CREATE, INSERT, UPDATE, DELETE, DROP and other operations that modify the server state.
The researcher also demonstrated an indirect prompt injection: an attacker with fewer privileges placed malicious instructions in database metadata, including through AGENTS.md or CONSTITUTION.md. When a privileged user accessed the object through Copilot, the instructions entered the model's context and triggered a bypass of read-only, after which arbitrary T-SQL was executed through the victim's connection. In the demonstration, this allowed privileges to be escalated from db_owner to the server role sysadmin.
Vulnerabilities
10
CVE-2026-65669
Vendors
Microsoft
Products
Copilot
Copilot For Sql Server Management Studio (Ssms)
Sp_Executesql
Sql Server
Sql Server Management Studio (Ssms)