SQL Copilot flaw: planted CONSTITUTION.md instructions let attackers become SYSADMIN

wunderwuzzi23 · x · 2026-10-01

Security researcher wunderwuzzi demonstrated a privilege escalation chain in SQL Copilot (CVE-2026-65669): a lower-privileged user (dbowner in the demo) can plant malicious CONSTITUTION.md instructions in a database. When a sysadmin later connects and uses Copilot, these attacker-controlled instructions trigger a read-only bypass and execute T-SQL with sysadmin privileges—letting the attacker add themselves as SYSADMIN. Microsoft has patched; the research was presented at Blue Hat Asia.

Related event: SQL Copilot Privilege Escalation Flaw Lets Low-Privilege Users Gain SYSADMIN(3 posts)→

Original post →

More from Safety

Safety channel →