Researcher hijacks Copilot in SQL Server Management Studio, escalating from SELECT to SYSADMIN (CVE-2026-65669)

wunderwuzzi23 · x · 2026-10-05

Security researcher wunderwuzzi published a demo showing a hijack of the Copilot assistant built into SQL Server Management Studio, tracked as CVE-2026-65669.

A textbook case of prompt injection escalating into real privilege compromise in AI security.

Original post →

More from coding & agent

coding & agent channel →