Critical Flaw in Microsoft's SQL Copilot Could Let Attackers Escalate to Admin
Security researcher Embrace The Red has published details on CVE-2026-65669, a critical SQL Server Elevation of Privilege vulnerability affecting Copilot integration in SQL Server Management Studio (SSMS). The research, first presented at BlueHat Asia 2026, found that Copilot executes database commands using the privileges of whichever user is connected through the Query Window. If that user has sysadmin rights, Copilot's actions inherit the same level of access.
The researcher discovered that Copilot's toolset expands significantly once an authenticated Query Window is opened, revealing tools for schema exploration, reading database content, running validation checks and more. One tool in particular, ReadFromDatabase, raised concerns about whether Copilot could be manipulated into running unintended or dangerous SQL commands. Microsoft's safeguard against this is a 'Read-Only' mode built into the system prompt, though the research suggests this protection may be bypassable, which is the basis for the critical severity rating.
Microsoft has rated this vulnerability as critical, meaning organisations using SSMS with Copilot enabled should prioritise patching. As this is an evolving area of AI integrated tooling, further technical details on exploitation were part of the ongoing presentation and are expected to be documented further.