From SELECT to SYSADMIN: Critical SQL Copilot privilege escalation flaw patched by Microsoft
wunderwuzzi23 · x · 2026-10-01
Security researcher wunderwuzzi presented research at BlueHat Asia 2026 on SQL Copilot in SQL Server Management Studio, uncovering CVE-2026-65669, a SQL Server elevation-of-privilege vulnerability rated critical by Microsoft and since patched.
Recon path: probing Copilot with list all your tools initially exposed only 5 tools; but after opening an authenticated query window, a much larger set of database-specific tools became available — schema exploration, retrieving query results, inspecting database objects, reading database content, T-SQL validation, backup operations and more. Chaining these tools enabled escalation from plain SELECT to SYSADMIN.
He also introduces the notion of a database "CONSTITUTION.md"; full write-up and video demos are on his blog. Users should update SSMS installations.
More from coding & agent
- Dev uses AI render projection to build Silent Hill-style Three.js kitchen with Astra — nptacek · 2026-10-01
- Tweet 'I need an app that...' and someone ships you an MVP in 30 minutes — thejasminejade · 2026-10-01
- 7-person robot startup Innate says Grok and Cursor let them do the work of 50 — Baconbrix · 2026-10-01
- Dev uses OpenAI's Dot to seamlessly monitor Claude Code benchmark on his machine — dkundel · 2026-10-01
- ChatGPT Sites Can Now Host MCP Servers, Auto-Deploying Plugins Across Platforms — OpenAIDevs · 2026-10-01
- Omnigent 0.16 ships with new file browser, admin controls and smoother onboarding — matei_zaharia · 2026-10-01