// AI threat desk · 1 Oct 2026
Home/ATK-AI · Attacks on AI
Attacks on AICriticalCVECVSS Not stated by source (Microsoft rates it Critical)

Research Reveals SQL Copilot Flaw CVE-2026-65669 Can Turn DB Users Into Admins

Researcher Johann Rehberger disclosed at BlueHat Asia 2026 that Copilot in Microsoft SQL Server Management Studio has CVE-2026-65669. Attackers can use indirect prompt injection and a regex guardrail flaw to escalate low-privilege database users to server-level sysadmin. Microsoft rates it ‘Critical’.

Illustrative image: a database server room.
File photo: Illustrative image: a database server room.. Photo: U.S. Forest Service (source) / rawpixel (CC0)
Key takeaways
  • Researcher Johann Rehberger disclosed CVE-2026-65669 at BlueHat Asia 2026, an SQL Server Copilot privilege escalation flaw rated ‘Critical’ by Microsoft
  • Attackers can use indirect prompt injection combined with a flaw in Copilot’s regex-based guardrail to bypass ‘read-only mode’ and run arbitrary T-SQL commands
  • The full attack chain can escalate a low-privilege db_owner-level user to a server-level sysadmin role
On this page

Researcher discloses SQL Copilot privilege escalation flaw at BlueHat Asia 2026

Researcher Johann Rehberger gave a talk at BlueHat Asia 2026 in Singapore covering his research into the built-in Copilot feature in Microsoft SQL Server Management Studio (SSMS). According to his blog post, the research concerns CVE-2026-65669, an Elevation of Privilege Vulnerability rated ‘Critical’ by Microsoft.

Microsoft has released a patch. Rehberger reminds users to confirm their installed version is updated.

Copilot executes commands with the connected user’s privileges

Rehberger found that when Copilot runs in SSMS, it uses the privileges of whichever user is currently connected to the query window. In other words, if a user connects as sysadmin, Copilot will also run SQL commands using that sysadmin connection.

One tool, ReadFromDatabase, can read database contents and is in theory restricted by ‘read-only mode’. The system prompt explicitly instructs the model not to run queries that would change the database or server state. But Rehberger notes that system prompt instructions are not a real security boundary.

Regex-based guardrail can be bypassed

Through reverse engineering of the relevant code, Rehberger found that read-only mode enforcement relies on a regex-based classifier inside the LocalSqlExecutionAccessChecker class. He points out that blocklist-based security controls are inherently fragile and often have multiple bypass paths.

For example, a statement such as DECLARE @p sysname='sp_who'; EXEC @p can bypass the blocklist, allowing any stored procedure to be called. Combined with sp_executesql, an attacker can execute dynamically constructed arbitrary SQL queries, including write operations such as CREATE, INSERT, UPDATE, DELETE and DROP.

Indirect prompt injection can leak data and seize sysadmin privileges

Rehberger demonstrated exfiltrating database contents row by row to a third-party server, using xp_dirtree and the RestoreVerifyBackupFile tool, which is designed to verify backup files.

More critically, SQL Copilot supports ‘database instructions’ stored as AGENTS.md and CONSTITUTION.md. These instructions are added as extended properties via the sp_addextendedproperty stored procedure, and Copilot automatically loads them into context. Rehberger notes that the privilege required to modify this metadata can be lower than that of the user who later uses Copilot, allowing a low-privilege user to influence the behaviour of a higher-privilege user’s AI agent.

In the final demonstration, a user with db_owner privileges planted a malicious ‘database constitution’. When Copilot loaded it, an indirect prompt injection triggered a read-only mode bypass, executing arbitrary T-SQL commands using the victim’s SQL connection. This ultimately added the attacker to the sysadmin role, completing the full attack chain from db_owner to system administrator.

Rehberger urges treating read-only guardrails as security invariants

Rehberger concludes that read-only guardrails for AI agents must be genuine security invariants, such as privilege controls, rather than relying solely on model instructions or a fragile SQL classifier. He also warns that if Copilot operates using a high-privilege database connection, any failure of agent controls can affect the entire system.

He further notes that persistent instructions such as AGENTS.md and CONSTITUTION.md introduce a new trust relationship into the database privilege model. Extended properties are no longer just metadata, they are instructions that the AI assistant will follow. This incident involves risks related to prompt injection and AI agents, and belongs to the same category of AI agent abuse as the earlier MCP Python SDK OAuth flaw.

What to do now

  1. Update SSMS and its Copilot feature to the latest patched version released by Microsoft
  2. Avoid connecting the query window with sysadmin or other high-privilege accounts before using Copilot, and instead connect with the minimum privileges necessary
  3. Use the administrative control options provided by Microsoft, including disabling Copilot, configuring group policy, or restricting the execution context
  4. Review AGENTS.md, CONSTITUTION.md and other extended properties in the database to confirm which users have permission to modify this metadata
  5. Verify the source of any content Copilot will read, such as files or table comments, to prevent indirect prompt injection

FAQ

Which products are affected by CVE-2026-65669?

The flaw affects the built-in Copilot feature in Microsoft SQL Server Management Studio (SSMS). Microsoft has rated it a ‘Critical’ privilege escalation vulnerability.

How can this vulnerability be exploited?

An attacker can plant malicious instructions in content that Copilot will read (indirect prompt injection), combined with bypassing the regex-based read-only mode guardrail, to execute arbitrary T-SQL commands. This can ultimately escalate a low-privilege database user to the sysadmin role.

What is indirect prompt injection?

Indirect prompt injection refers to an attacker hiding malicious instructions inside content that an AI agent will read, such as files, database comments, or metadata. When another user’s agent reads that content, it can be manipulated into executing the attacker’s instructions.

Has this vulnerability been used in real attacks?

The article does not mention this vulnerability being used in real attacks. The content is a research disclosure presented by the researcher at the BlueHat Asia 2026 conference.

What should administrators do now?

Administrators should update SSMS to the latest patched version, avoid using Copilot after connecting with high-privilege accounts, and review who has permission to modify extended properties such as AGENTS.md and CONSTITUTION.md.

Sources

  1. From SELECT to SYSADMIN with SQL Copilot (CVE-2026-65669), embracethered.comPrimary
  2. CVE-2026-65669, Microsoft Security Response CenterPrimary
Explore with AI