{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/embrace-the-red-sql-copilot-ssms-cve-2026-65669-2026/",
 "asOf": "2026-10-01",
 "id": "embrace-the-red-sql-copilot-ssms-cve-2026-65669-2026",
 "date": "2026-09-30",
 "datePrecision": "day",
 "title": "Researcher reports Copilot in SQL Server Management Studio acts with the connected user's privileges, rated critical (CVE-2026-65669)",
 "lane": "attack",
 "kind": "vulnerability-disclosure",
 "summary": "Johann Rehberger (Embrace The Red) writes up a BlueHat Asia 2026 talk on Microsoft's Copilot in SQL Server Management Studio, reporting that the assistant runs database actions with the privileges of whoever is connected and that its \"read-only\" mode rested on a prompt instruction and a pattern-matching filter rather than a permission. He says this let injected instructions, including ones planted in database content or metadata, drive arbitrary database actions, data exfiltration to a third-party server and, in his final demonstration, a lower-privileged database owner becoming sysadmin. Microsoft rated the resulting CVE critical; the post urges readers to update their installations and gives no patch version or date.",
 "whyItMatters": "It is a researcher's account of an agent that inherits its user's database privileges, where a read-only restriction was not enforced as a permission and low-privilege users could write instructions the agent later followed.",
 "actors": [
  "embrace-the-red",
  "microsoft"
 ],
 "topics": [
  "prompt-injection",
  "tool-and-mcp-security",
  "data-exfiltration",
  "access-controls"
 ],
 "atlas": [
  "untrusted-content",
  "tools",
  "credentials"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://embracethered.com/blog/posts/2026/from-select-to-sysadmin-sql-copilot-bluehat-asia/",
   "publisher": "Embrace The Red",
   "title": "From SELECT to SYSADMIN with SQL Copilot (CVE-2026-65669)",
   "date": "2026-09-30",
   "type": "primary",
   "accessed": "2026-10-01"
  }
 ],
 "keyFacts": [
  {
   "fact": "The researcher says the post covers CVE-2026-65669, which Microsoft titles a SQL Server Elevation of Privilege Vulnerability and rated critical. His initial research was in May 2026, and the talk was given at BlueHat Asia 2026 in Singapore about two weeks before the post. The post has no date in its archived text; 2026-09-30 is the publication date in the site's RSS feed.",
   "locator": "Opening; Indirect Prompt Injection Attack Paths; site feed"
  },
  {
   "fact": "Patch status: the post tells readers to make sure their installations are updated, which implies a fix exists, but it does not name a fixed version or release date. The CVE record at Microsoft's update guide is linked but was not archived or read for this record.",
   "locator": "Opening; References"
  },
  {
   "fact": "The researcher reports that Copilot inherits the connected user’s database privileges. He demonstrates indirect prompt injection causing unauthorized database actions and data exposure, including a case where a database owner’s instructions were later processed in a higher-privilege context and resulted in sysadmin access.",
   "locator": "Reconnaissance: From SELECT to SYSADMIN; Indirect Prompt Injection Attack Paths; From Database Owner to SYSADMIN"
  },
  {
   "fact": "The researcher reports that the system prompt tells the model it is in a read-only mode, and that the model refused obvious write requests, but that the real enforcement was a pattern-matching filter, with no separate low-privileged connection or read-only permission. He says bypasses were found quickly with AI help and that the read-only restriction could be turned into write capability.",
   "locator": "The ReadFromDatabase Tool; Breaking Read-Only Mode; Executing Dynamic and Arbitrary SQL"
  },
  {
   "fact": "The researcher's takeaways: enforce read-only as a security invariant rather than a model instruction or fragile filter; do not connect Copilot with highly privileged accounts; indirect injection becomes serious when the agent can run arbitrary T-SQL; letting users choose the underlying model may weaken safety if some models resist adversarial instructions less; and persistent instruction files add new trust relationships to the database permission model. He notes Microsoft has administrative controls to disable Copilot, set group policies and set an execution context.",
   "locator": "Mitigations and Conclusion"
  }
 ],
 "significance": 3,
 "fideQuestions": [
  "FID-074"
 ],
 "methods": [
  "agent-data-exfiltration",
  "credential-overreach",
  "indirect-prompt-injection"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-10-01"
}