Researcher hijacks Copilot in SQL Server Management Studio, escalating from SELECT to SYSADMIN (CVE-2026-65669)
wunderwuzzi23 · x · 2026-10-05
Security researcher wunderwuzzi published a demo showing a hijack of the Copilot assistant built into SQL Server Management Studio, tracked as CVE-2026-65669.
- The attack starts from a mere SELECT query, injecting instructions into the Copilot context
- It escalates privileges all the way to SYSADMIN
- The demo highlights how embedding AI assistants into database tooling expands the attack surface from code completion to the database permission chain
A textbook case of prompt injection escalating into real privilege compromise in AI security.
More from coding & agent
- Opus 5.5 directed a film in under 16 seconds, scripting and editing itself — gouterz · 2026-10-05
- Dev parodies AI disclosure: "I admit I used IntelliSense and syntax highlighting" — uwukko · 2026-10-05
- Line-by-line code review can't scale with AI agents, so these devs went function-level — Wise_Reflection_8340 · 2026-10-05
- Notion exec concedes integrations lag as users go chat-first with MCP — nbaschez · 2026-10-05
- Agent harnesses should emerge from building, not be built for their own sake — kevinnbass · 2026-10-05
- Fine-tuned 350M model lifts PII removal from 89.7% to 99.7% — JosephJacks_ · 2026-10-05