SQL Copilot Privilege Escalation Flaw Lets Low-Privilege Users Gain SYSADMIN
Security researcher wunderwuzzi demonstrated at BlueHat Asia 2026 that SQL Copilot in SSMS is vulnerable to privilege escalation (CVE-2026-65669). Low-privilege users can plant malicious instructions via CONSTITUTION.md to trick the AI into granting SYSADMIN, earning acknowledgment from Microsoft.
2026-10-01 ~ 2026-10-01 · 3 related posts
- From SELECT to SYSADMIN: Critical SQL Copilot privilege escalation flaw patched by Microsoft — wunderwuzzi23 · 2026-10-01
- SQL Copilot flaw: planted CONSTITUTION.md instructions let attackers become SYSADMIN — wunderwuzzi23 · 2026-10-01
1 near-duplicate retellings: wunderwuzzi23