# SQL Server Copilot: prompt injection escalates a user to sysadmin

> Instructions planted in database metadata made Copilot run write queries as whichever admin used it next.

- **Severity:** High: A working attack on a widely used AI product or ecosystem. A fix may exist. Patch or mitigate this week.
- **Category:** Vulnerability, Attack
- **Published by:** Embrace The Red
- **Disclosed:** 2026-09-08
- **CVE:** CVE-2026-65669
- **CVSS:** 9.6
- **Affects:** SQL Server Management Studio 22, GitHub Copilot in SSMS
- **Research by:** [Johann Rehberger](https://embracethered.com/blog/)
- **Primary source:** https://embracethered.com/blog/posts/2026/from-select-to-sysadmin-sql-copilot-bluehat-asia/
- **Page:** https://theinjection.dev/items/embracethered-ssms-copilot-select-to-sysadmin/

CVE-2026-65669 let indirect prompt injection push GitHub Copilot in SQL Server Management Studio past its read-only mode and run T-SQL with a sysadmin's privileges. Microsoft rates it CVSS 9.6; SSMS 22.8.2 fixes it.

## What happened

Microsoft published CVE-2026-65669, a SQL Server elevation of privilege flaw rated CVSS 9.6, on September 8, 2026. Johann Rehberger of Embrace The Red found the issue in May 2026, presented it at BlueHat Asia 2026 and published the full write-up on September 30, 2026.

## How it works

Copilot's read-only mode was enforced by a regex check in the LocalSqlExecutionAccessChecker class and by the system prompt, not by database permissions. Indirect calls such as DECLARE @p sysname='sp_executesql'; EXEC @p got past the blocklist. A lower-privileged user can plant instructions in database extended properties such as AGENTS.md or CONSTITUTION.md, and when a sysadmin later uses Copilot, those instructions run with the sysadmin's rights, with data sent out through xp_dirtree SMB paths.

## Who is affected

Users of SQL Server Management Studio 22 from version 22.0 up to but not including 22.8.2 who use GitHub Copilot, especially administrators connected with high privileges to databases that other users can modify.

## What to do

Update SSMS to 22.8.2 or later. Do not connect Copilot with sysadmin credentials, and use Microsoft's new admin controls to disable Copilot or restrict its execution context where high privileges are in use.

## Quick facts

- **CVE:** CVE-2026-65669
- **CVSS 3.1:** 9.6 (Microsoft)
- **Affected:** SSMS 22.0 to before 22.8.2
- **Attack type:** Indirect prompt injection, read-only bypass
- **Found by:** Johann Rehberger (Embrace The Red)
- **New controls:** Admin and group policy controls for Copilot in SSMS

## Questions

### Which SSMS version fixes CVE-2026-65669?

SQL Server Management Studio 22.8.2 fixes CVE-2026-65669, according to Microsoft's CVE record, which lists SSMS 22 from version 22.0 up to but not including 22.8.2 as affected. Administrators who use GitHub Copilot in SSMS should update first, then review the new Copilot admin controls Microsoft documented for the product.

### Can I turn off GitHub Copilot in SQL Server Management Studio?

GitHub Copilot in SQL Server Management Studio can be turned off. After Johann Rehberger's report, Microsoft documented admin controls that disable Copilot entirely, set it through group policy, and limit the execution context Copilot uses. Teams that connect to production databases with high privileges should use these controls, not rely on Copilot's read-only setting.

### Why did the SSMS Copilot read-only mode fail?

The SSMS Copilot read-only mode failed because it was a regex classifier plus a system prompt, not a database permission. Johann Rehberger showed that an indirect call such as EXEC on a variable holding sp_executesql passed the blocklist. His conclusion is that read-only access for an AI agent must be enforced like a permission, not as a model instruction.

## Sources

1. [Embrace The Red Post](https://embracethered.com/blog/posts/2026/from-select-to-sysadmin-sql-copilot-bluehat-asia/)
2. [CVE Record](https://cveawg.mitre.org/api/cve/CVE-2026-65669)
3. [SSMS Copilot Controls](https://learn.microsoft.com/en-us/ssms/github-copilot/admin-controls)
