SQL Copilot Privilege Escalation Flaw Lets Low-Privilege Users Gain SYSADMIN

Security researcher wunderwuzzi demonstrated at BlueHat Asia 2026 that SQL Copilot in SSMS is vulnerable to privilege escalation (CVE-2026-65669). Low-privilege users can plant malicious instructions via CONSTITUTION.md to trick the AI into granting SYSADMIN, earning acknowledgment from Microsoft.

2026-10-01 ~ 2026-10-01 · 3 related posts

1 near-duplicate retellings: wunderwuzzi23