From SELECT to SYSADMIN: Critical SQL Copilot privilege escalation flaw patched by Microsoft

wunderwuzzi23 · x · 2026-10-01

Security researcher wunderwuzzi presented research at BlueHat Asia 2026 on SQL Copilot in SQL Server Management Studio, uncovering CVE-2026-65669, a SQL Server elevation-of-privilege vulnerability rated critical by Microsoft and since patched.

Recon path: probing Copilot with list all your tools initially exposed only 5 tools; but after opening an authenticated query window, a much larger set of database-specific tools became available — schema exploration, retrieving query results, inspecting database objects, reading database content, T-SQL validation, backup operations and more. Chaining these tools enabled escalation from plain SELECT to SYSADMIN.

He also introduces the notion of a database "CONSTITUTION.md"; full write-up and video demos are on his blog. Users should update SSMS installations.

Related event: SQL Copilot Privilege Escalation Flaw Lets Low-Privilege Users Gain SYSADMIN(3 posts)→

Original post →

More from coding & agent

coding & agent channel →