Threat · curated 1 Oct 2026

From SELECT to SYSADMIN with SQL Copilot (CVE-2026-65669)

Dossier

Coverage timeline

30 Sep 2026embracethered.comprimary

Single-source research — first reported, latest, and curated coincide.

Why it matters

CVE-2026-65669 shows that an AI copilot's guardrails enforced only through a system prompt can be jailbroken to execute privileged database operations as the connected user, turning a database assistant into a privilege-escalation vector.

Johann Rehberger disclosed CVE-2026-65669, a critical SQL Server elevation-of-privilege vulnerability in Microsoft's Copilot integrated into SQL Server Management Studio (SSMS), presented at BlueHat Asia 2026. Copilot executes T/SQL with the connected user's privileges (including sysadmin) and its 'read-only' restriction, enforced only via the system prompt, can be bypassed to escalate from SELECT access to SYSADMIN. Microsoft rated the flaw critical and users are urged to update.

vuln-research

Summary

Security researcher Johann Rehberger disclosed CVE-2026-65669, a critical Microsoft SQL Server Elevation of Privilege vulnerability in the Copilot feature of SQL Server Management Studio (SSMS), in a BlueHat Asia 2026 presentation. Copilot executes T/SQL with the privileges of the connected user, and its 'read-only' protection is enforced only by a fragile regex-based classifier rather than a real security boundary.[0][1][7]

The researcher demonstrated that the read-only blocklist can be bypassed (for example using DECLARE @p sysname='sp_executesql'; EXEC @p) to run arbitrary CREATE/INSERT/UPDATE/DELETE/DROP statements, exfiltrate data via xp_dirtree over SMB and the RestoreVerifyBackupFile tool, and ultimately chain indirect prompt injection via planted AGENTS.md/CONSTITUTION.md database instructions to escalate a db_owner to the SQL Server sysadmin role.[0]

Attack chain

  1. Reconnaissance: The researcher enumerated Copilot's available tools (e.g., ReadFromDatabase, RestoreVerifyBackupFile) and retrieved the Copilot system prompt from %APPDATA%\Local\SSMSCopilot chat logs, learning that read-only mode was declared only as a model instruction.[0][2]
  2. Read-only bypass: Reverse engineering the ReadFromDatabase tool with ILSpy revealed the LocalSqlExecutionAccessChecker regex blocklist, which was bypassed using patterns like DECLARE @p sysname='sp_executesql'; EXEC @p to execute arbitrary dynamic SQL.[0]
  3. Data exfiltration: Arbitrary SQL primitives were used to exfiltrate table data row-by-row via xp_dirtree to an attacker SMB path, and separately via the RestoreVerifyBackupFile tool which allowed arbitrary T/SQL passthrough.[0]
  4. Indirect prompt injection persistence: A lower-privileged user planted malicious instructions as AGENTS.md/CONSTITUTION.md extended properties via sp_addextendedproperty, which Copilot automatically loads into context when another, higher-privileged user interacts with the object.[0]
  5. Privilege escalation: When a sysadmin-connected victim used Copilot, the planted constitution triggered the read-only bypass to execute arbitrary T/SQL under the victim's connection, adding the attacker's login to the SQL Server sysadmin role, elevating db_owner to sysadmin.[0]

Disclosure timeline

DateEvent
May 2026Initial research conducted on SQL Copilot in SSMS; system prompt captured at this time.[0]
2026 (BlueHat Asia, Singapore)Johann Rehberger presented the research on CVE-2026-65669 at BlueHat Asia 2026, roughly two weeks before the write-up.[0]

How it works

Copilot in SSMS runs T/SQL using the connection of the Query Window, inheriting the connected user's privileges (including sysadmin). Its 'read-only mode' is declared in the system prompt as a model instruction rather than being enforced as a permission.[0]

The only actual enforcement for the ReadFromDatabase tool is a regex-based classifier in the LocalSqlExecutionAccessChecker class that blocks patterns such as EXEC. Because blocklists are fragile, invocations like DECLARE @p sysname='sp_who'; EXEC @p or DECLARE @p sysname='sp_executesql'; EXEC @p N'DROP TABLE [Test];' bypass the filter and allow arbitrary stored-procedure and dynamic SQL execution, converting read-only mode into write mode.[0]

Database instructions stored as AGENTS.md (object-level) and CONSTITUTION.md (database-wide) extended properties, added via sp_addextendedproperty, are automatically discovered and incorporated into Copilot's prompt context. A user needing only ALTER permission on an object can attach these, allowing a lower-privileged user to inject instructions that a higher-privileged user's Copilot session will later execute — an indirect prompt injection that enables privilege escalation to sysadmin.[0]

Affected versions and patch status

ProductAffectedPatch status
Microsoft SQL Server / Copilot in SQL Server Management Studio (SSMS)SSMS installations with Copilot enabled (research conducted May 2026); MCP support later added by MicrosoftRated critical by Microsoft; users advised to keep installations up to date. Microsoft provides administrative controls to disable Copilot, apply group policies, and set an execution context.[0][1][6]

Key takeaways

  • Read-only enforcement for an AI agent must be a security invariant such as a permission or a low-privileged connection, not a model instruction or a fragile SQL regex classifier.[0]
  • Copilot in SSMS should not be run under highly privileged connections because the agent executes T/SQL with the connected user's privileges, making sysadmin connections especially dangerous.[0]
  • Persistent database instructions like AGENTS.md and CONSTITUTION.md, stored as extended properties, create new trust relationships: a lower-privileged user can inject instructions that a higher-privileged user's Copilot will execute, enabling indirect prompt injection and privilege escalation to sysadmin.[0]

Defensive actions

  • Keep SQL Server / SSMS Copilot installations up to date with Microsoft's patch for CVE-2026-65669.: Microsoft rated the elevation-of-privilege vulnerability critical and the researcher explicitly advised ensuring installations are current.[0][1]
  • Avoid operating Copilot in SSMS using highly privileged database connections (e.g., sysadmin).: Copilot executes with the privileges of the connected user, so a control failure under a sysadmin connection has system-wide impact.[0]
  • Apply Microsoft's administrative controls for SQL Copilot — disabling Copilot, configuring group policies, and setting a restricted execution context.: These controls limit Copilot's capabilities and reduce the blast radius of the read-only bypass and prompt-injection paths.[0][6]
  • Treat read-only enforcement for AI agents as a real security invariant (permission/least-privilege connection), not a model instruction or regex classifier, and govern who can write AGENTS.md/CONSTITUTION.md extended properties.: The regex blocklist was trivially bypassed and extended-property instructions introduce new trust relationships that bypass the database permission model.[0]