Threat · curated 1 Oct 2026
From SELECT to SYSADMIN with SQL Copilot (CVE-2026-65669)
First reported embracethered.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
CVE-2026-65669 shows that an AI copilot's guardrails enforced only through a system prompt can be jailbroken to execute privileged database operations as the connected user, turning a database assistant into a privilege-escalation vector.
Johann Rehberger disclosed CVE-2026-65669, a critical SQL Server elevation-of-privilege vulnerability in Microsoft's Copilot integrated into SQL Server Management Studio (SSMS), presented at BlueHat Asia 2026. Copilot executes T/SQL with the connected user's privileges (including sysadmin) and its 'read-only' restriction, enforced only via the system prompt, can be bypassed to escalate from SELECT access to SYSADMIN. Microsoft rated the flaw critical and users are urged to update.
Summary
Security researcher Johann Rehberger disclosed CVE-2026-65669, a critical Microsoft SQL Server Elevation of Privilege vulnerability in the Copilot feature of SQL Server Management Studio (SSMS), in a BlueHat Asia 2026 presentation. Copilot executes T/SQL with the privileges of the connected user, and its 'read-only' protection is enforced only by a fragile regex-based classifier rather than a real security boundary.[0][1][7]
The researcher demonstrated that the read-only blocklist can be bypassed (for example using DECLARE @p sysname='sp_executesql'; EXEC @p) to run arbitrary CREATE/INSERT/UPDATE/DELETE/DROP statements, exfiltrate data via xp_dirtree over SMB and the RestoreVerifyBackupFile tool, and ultimately chain indirect prompt injection via planted AGENTS.md/CONSTITUTION.md database instructions to escalate a db_owner to the SQL Server sysadmin role.[0]
Attack chain
- Reconnaissance: The researcher enumerated Copilot's available tools (e.g., ReadFromDatabase, RestoreVerifyBackupFile) and retrieved the Copilot system prompt from %APPDATA%\Local\SSMSCopilot chat logs, learning that read-only mode was declared only as a model instruction.[0][2]
- Read-only bypass: Reverse engineering the ReadFromDatabase tool with ILSpy revealed the LocalSqlExecutionAccessChecker regex blocklist, which was bypassed using patterns like DECLARE @p sysname='sp_executesql'; EXEC @p to execute arbitrary dynamic SQL.[0]
- Data exfiltration: Arbitrary SQL primitives were used to exfiltrate table data row-by-row via xp_dirtree to an attacker SMB path, and separately via the RestoreVerifyBackupFile tool which allowed arbitrary T/SQL passthrough.[0]
- Indirect prompt injection persistence: A lower-privileged user planted malicious instructions as AGENTS.md/CONSTITUTION.md extended properties via sp_addextendedproperty, which Copilot automatically loads into context when another, higher-privileged user interacts with the object.[0]
- Privilege escalation: When a sysadmin-connected victim used Copilot, the planted constitution triggered the read-only bypass to execute arbitrary T/SQL under the victim's connection, adding the attacker's login to the SQL Server sysadmin role, elevating db_owner to sysadmin.[0]
Disclosure timeline
| Date | Event |
|---|---|
| May 2026 | Initial research conducted on SQL Copilot in SSMS; system prompt captured at this time.[0] |
| 2026 (BlueHat Asia, Singapore) | Johann Rehberger presented the research on CVE-2026-65669 at BlueHat Asia 2026, roughly two weeks before the write-up.[0] |
How it works
Copilot in SSMS runs T/SQL using the connection of the Query Window, inheriting the connected user's privileges (including sysadmin). Its 'read-only mode' is declared in the system prompt as a model instruction rather than being enforced as a permission.[0]
The only actual enforcement for the ReadFromDatabase tool is a regex-based classifier in the LocalSqlExecutionAccessChecker class that blocks patterns such as EXEC. Because blocklists are fragile, invocations like DECLARE @p sysname='sp_who'; EXEC @p or DECLARE @p sysname='sp_executesql'; EXEC @p N'DROP TABLE [Test];' bypass the filter and allow arbitrary stored-procedure and dynamic SQL execution, converting read-only mode into write mode.[0]
Database instructions stored as AGENTS.md (object-level) and CONSTITUTION.md (database-wide) extended properties, added via sp_addextendedproperty, are automatically discovered and incorporated into Copilot's prompt context. A user needing only ALTER permission on an object can attach these, allowing a lower-privileged user to inject instructions that a higher-privileged user's Copilot session will later execute — an indirect prompt injection that enables privilege escalation to sysadmin.[0]
Affected versions and patch status
| Product | Affected | Patch status |
|---|---|---|
| Microsoft SQL Server / Copilot in SQL Server Management Studio (SSMS) | SSMS installations with Copilot enabled (research conducted May 2026); MCP support later added by Microsoft | Rated critical by Microsoft; users advised to keep installations up to date. Microsoft provides administrative controls to disable Copilot, apply group policies, and set an execution context.[0][1][6] |
Key takeaways
- Read-only enforcement for an AI agent must be a security invariant such as a permission or a low-privileged connection, not a model instruction or a fragile SQL regex classifier.[0]
- Copilot in SSMS should not be run under highly privileged connections because the agent executes T/SQL with the connected user's privileges, making sysadmin connections especially dangerous.[0]
- Persistent database instructions like AGENTS.md and CONSTITUTION.md, stored as extended properties, create new trust relationships: a lower-privileged user can inject instructions that a higher-privileged user's Copilot will execute, enabling indirect prompt injection and privilege escalation to sysadmin.[0]
Defensive actions
- Keep SQL Server / SSMS Copilot installations up to date with Microsoft's patch for CVE-2026-65669.: Microsoft rated the elevation-of-privilege vulnerability critical and the researcher explicitly advised ensuring installations are current.[0][1]
- Avoid operating Copilot in SSMS using highly privileged database connections (e.g., sysadmin).: Copilot executes with the privileges of the connected user, so a control failure under a sysadmin connection has system-wide impact.[0]
- Apply Microsoft's administrative controls for SQL Copilot — disabling Copilot, configuring group policies, and setting a restricted execution context.: These controls limit Copilot's capabilities and reduce the blast radius of the read-only bypass and prompt-injection paths.[0][6]
- Treat read-only enforcement for AI agents as a real security invariant (permission/least-privilege connection), not a model instruction or regex classifier, and govern who can write AGENTS.md/CONSTITUTION.md extended properties.: The regex blocklist was trivially bypassed and extended-property instructions introduce new trust relationships that bypass the database permission model.[0]