SQL Server Copilot: prompt injection escalates a user to sysadmin
Instructions planted in database metadata made Copilot run write queries as whichever admin used it next.
· Embrace The Red · Research by Johann Rehberger

CVE-2026-65669 let indirect prompt injection push GitHub Copilot in SQL Server Management Studio past its read-only mode and run T-SQL with a sysadmin's privileges. Microsoft rates it CVSS 9.6; SSMS 22.8.2 fixes it.
- embracethered.comEmbrace The Red Post
- cveawg.mitre.orgCVE Record
- learn.microsoft.comSSMS Copilot Controls
01What happened
Microsoft published CVE-2026-65669, a SQL Server elevation of privilege flaw rated CVSS 9.6, on September 8, 2026. Johann Rehberger of Embrace The Red found the issue in May 2026, presented it at BlueHat Asia 2026 and published the full write-up on September 30, 2026.
02How it works
Copilot's read-only mode was enforced by a regex check in the LocalSqlExecutionAccessChecker class and by the system prompt, not by database permissions. Indirect calls such as DECLARE @p sysname='sp_executesql'; EXEC @p got past the blocklist. A lower-privileged user can plant instructions in database extended properties such as AGENTS.md or CONSTITUTION.md, and when a sysadmin later uses Copilot, those instructions run with the sysadmin's rights, with data sent out through xp_dirtree SMB paths.
03Who is affected
Users of SQL Server Management Studio 22 from version 22.0 up to but not including 22.8.2 who use GitHub Copilot, especially administrators connected with high privileges to databases that other users can modify.
04What to do
Update SSMS to 22.8.2 or later. Do not connect Copilot with sysadmin credentials, and use Microsoft's new admin controls to disable Copilot or restrict its execution context where high privileges are in use.
Questions people ask
- Which SSMS version fixes CVE-2026-65669?
- SQL Server Management Studio 22.8.2 fixes CVE-2026-65669, according to Microsoft's CVE record, which lists SSMS 22 from version 22.0 up to but not including 22.8.2 as affected. Administrators who use GitHub Copilot in SSMS should update first, then review the new Copilot admin controls Microsoft documented for the product.
- Can I turn off GitHub Copilot in SQL Server Management Studio?
- GitHub Copilot in SQL Server Management Studio can be turned off. After Johann Rehberger's report, Microsoft documented admin controls that disable Copilot entirely, set it through group policy, and limit the execution context Copilot uses. Teams that connect to production databases with high privileges should use these controls, not rely on Copilot's read-only setting.
- Why did the SSMS Copilot read-only mode fail?
- The SSMS Copilot read-only mode failed because it was a regex classifier plus a system prompt, not a database permission. Johann Rehberger showed that an indirect call such as EXEC on a variable holding sp_executesql passed the blocklist. His conclusion is that read-only access for an AI agent must be enforced like a permission, not as a model instruction.
Sources 3 links, all fetched
- 1embracethered.comEmbrace The Red Post
- 2cveawg.mitre.orgCVE Record
- 3learn.microsoft.comSSMS Copilot Controls