SQL Copilot flaw: planted CONSTITUTION.md instructions let attackers become SYSADMIN
wunderwuzzi23 · x · 2026-10-01
Security researcher wunderwuzzi demonstrated a privilege escalation chain in SQL Copilot (CVE-2026-65669): a lower-privileged user (dbowner in the demo) can plant malicious CONSTITUTION.md instructions in a database. When a sysadmin later connects and uses Copilot, these attacker-controlled instructions trigger a read-only bypass and execute T-SQL with sysadmin privileges—letting the attacker add themselves as SYSADMIN. Microsoft has patched; the research was presented at Blue Hat Asia.
More from Safety
- Researchers flag AI "delusional spiraling": sycophantic models amplify users' false beliefs — QuintinPope5 · 2026-10-01
- Senator Warns There Is No Kill Switch or Failsafe if AI Goes Wrong Fast — MariusHobbhahn · 2026-10-01
- California Bans Employers From Using AI to Monitor Workers' Brains and Emotions — bloomberglaw · 2026-10-01
- OpenAI's Greg Brockman Pulls Out of Second $25M Donation to AI Super PAC — pstAsiatech · 2026-10-01
- Fact-check: the 300-hour AI psychosis case involved GPT-4o, and the cited paper modeled safeguards, not proof of intent — ChrisGPT · 2026-10-01
- Data standards could unlock AI gains in clinical trials, extending benefits to LMICs — iskander · 2026-10-01