PT-2026-87215 · Microsoft · Sql Server+1
CVE-2026-65669
·
Published
2026-09-08
·
Updated
2026-10-06
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SQL Server (affected versions not specified)
Description
Improper neutralization of special elements in output used by a downstream component (injection) allows an unauthorized attacker to elevate privileges over a network. When using SQL Copilot in SQL Server Management Studio, crafted instructions can cause the system to act using the user's database permissions, as it treats these instructions as untrusted input.
Recommendations
Apply the current month's update for SQL Server.
Treat all instructions passed to SQL Copilot as untrusted input.
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sql Server
Sql Server Management Studio