SQL Copilot critical flaw lets low-privilege users escalate to SYSADMIN via CONSTITUTION.md
wunderwuzzi23 · x · 2026-10-01
Security researcher wunderwuzzi presented and published details of a critical privilege escalation flaw (CVE-2026-65669) in SQL Copilot inside SQL Server Management Studio at Blue Hat Asia 2026:
- Attack chain: a low-privilege user (dbowner in the demo) plants malicious CONSTITUTION.md instructions in a database. When a sysadmin later connects and uses Copilot, these attacker-controlled instructions trigger a read-only bypass and execute T-SQL with sysadmin privileges—letting the attacker add themselves as SYSADMIN.
- Recon: asking Copilot to "list all your tools" revealed only 5 tools; opening an authenticated query window exposed a far larger toolset—schema exploration, query result retrieval, object inspection, T-SQL validation, backups, and more.
- Microsoft has patched; the author urges users to update SSMS. Full technical writeup and video demos are on his blog, Embrace The Red.
More from Safety
- Researchers flag AI "delusional spiraling": sycophantic models amplify users' false beliefs — QuintinPope5 · 2026-10-01
- Senator Warns There Is No Kill Switch or Failsafe if AI Goes Wrong Fast — MariusHobbhahn · 2026-10-01
- California Bans Employers From Using AI to Monitor Workers' Brains and Emotions — bloomberglaw · 2026-10-01
- OpenAI's Greg Brockman Pulls Out of Second $25M Donation to AI Super PAC — pstAsiatech · 2026-10-01
- Fact-check: the 300-hour AI psychosis case involved GPT-4o, and the cited paper modeled safeguards, not proof of intent — ChrisGPT · 2026-10-01
- Data standards could unlock AI gains in clinical trials, extending benefits to LMICs — iskander · 2026-10-01