Microsoft's rating for CVE-2026-65669: Critical (Source: Embrace The Red, citing Microsoft's CVE-2026-65669 rating (September 30, 2026))
An assistant with the keys, taking notes from anyone
An AI assistant that acts for you uses your permissions. If someone else can change what it reads, they can borrow those permissions.
Security teams call this a confused deputy. A trusted helper is tricked into using its authority for someone else.
The researcher behind the Embrace The Red blog has shown this problem in Copilot for SQL Server Management Studio (SSMS). SSMS is the tool many teams use to run their databases. The researcher presented the work at BlueHat Asia 2026.
The talk covered CVE-2026-65669, which Microsoft rates critical. It is an elevation of privilege vulnerability in SQL Server. The researcher's advice is short: make sure installations are up to date.
How the read-only promise broke
Copilot uses the connection from the open Query Window. If the user is connected as sysadmin, Copilot runs its SQL as sysadmin too. Sysadmin is the top administrative role in SQL Server.
Copilot was meant to be read-only. Its system prompt, the hidden brief given to the model, told it not to change database or server state.
The model did refuse obvious requests. When asked to call xp_dirtree, a procedure that connects to a remote server, it said no.
But a rule written into a prompt is only a request to the model. The researcher checked whether anything else enforced it.
The researcher reverse engineered the code. The real check was a regex-based classifier in a class called LocalSqlExecutionAccessChecker. A regex classifier is a list of text patterns to block.
The researcher found no separate low-privileged connection behind it. There was no read-only permission either.
With AI help, bypasses came quickly. The pattern DECLARE @p sysname='sp_who'; EXEC @p slipped past the block on EXEC. It could call any stored procedure.
Another route used sp_executesql, which runs queries built on the fly. After that, the researcher reports, Copilot could run CREATE, INSERT, UPDATE, DELETE and DROP.
Two ways to send data out
The researcher demonstrated two routes for moving data to outside systems.
In the first, Copilot read a table. It then placed each row inside an SMB network path passed to xp_dirtree. Each row reached a third-party server.
In the second, a tool called RestoreVerifyBackupFile was meant only to verify backups. Its code let arbitrary T/SQL pass through and run.
Notes that give orders
Direct prompting needs the attacker at the keyboard. The bigger finding is that SQL Copilot takes in a lot of context. It pulls in table contents, script files, the database layout and descriptive metadata.
The researcher showed a comment in a file hijacking Copilot. Another user asked Copilot to inspect that file. Copilot then used the bypass to run an UPDATE.
Then came the feature that changes the trust picture. SQL Copilot supports database instructions, stored as extended properties. These are notes attached to database objects.
A CONSTITUTION.md applies to the whole database. An AGENTS.md can apply to one table or column. Copilot finds both on its own and adds them to its prompt.
The rights needed to write these notes can be lower than the rights of the person who later uses Copilot. Holding ALTER rights on a single object is enough to leave standing instructions on it for Copilot.
In the final demo, a db_owner planted instructions. A sysadmin's Copilot loaded them. The attacker's login was added to the sysadmin role.
What this shows
The lesson is narrow. Database metadata used to be plain data. Once an AI assistant reads it, it becomes instructions.
Whoever can edit that metadata gains a say over the reader's authority. The researcher says the same: extended properties end up as instructions an AI assistant will follow.
This covers one product and one researcher's findings. It does not report attacks in the wild.
The research began in May 2026. The post notes Microsoft has since added MCP support, so the tool has changed.
Questions for your database and security teams
First, confirm SSMS and SQL Server installations are up to date, including any fix for CVE-2026-65669.
Second, ask who connects to Copilot as sysadmin. The researcher advises against highly privileged connections. If the agent's controls fail, the impact reaches the whole system.
Third, review who holds ALTER rights on objects. They can now shape what an assistant does. Microsoft offers controls to disable Copilot, set group policy and set an execution context.
Fourth, ask vendors how they enforce read-only. The researcher wants a fixed rule like a permission. A model's instructions or a list of blocked text patterns are not enough.
A prompt states an intention. A permission enforces it. Pay for the second.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Embrace The Red.





