At BlueHat Asia 2026 in Singapore, researcher Johann Rehberger (Embrace The Red) presented "From SELECT to SYSADMIN with SQL Copilot," disclosing CVE-2026-65669 — a critical unauthorized privilege escalation vulnerability in Microsoft SQL Server, exposed through the Copilot integration in SQL Server Management Studio (SSMS). Microsoft has rated the vulnerability Critical and released fixes. If your organization runs SSMS 21.x with Copilot features enabled against production SQL Server instances, treat this as an urgent patching event.
This is a landmark case for defenders: it is one of the first critical CVEs where an AI assistant embedded in a trusted administrative tool becomes the escalation vector. The defensive lesson extends beyond one patch — every copilot, agent, or LLM-integrated console that operates with the user's credentials is now part of your attack surface and must be governed accordingly.
Technical Analysis
What is affected
- Product: Microsoft SQL Server, in combination with Copilot in SQL Server Management Studio (SSMS)
- Component: The Copilot chat/agent feature in SSMS, which can generate and execute T-SQL in the context of the connected session
- Impact: Unauthorized privilege gain — a principal holding low-privilege database access (e.g.,
SELECT-only rights) can be escalated to sysadmin on the SQL Server instance - CVE: CVE-2026-65669 (rated Critical by Microsoft)
How the attack works (defender's view)
Copilot in SSMS executes generated T-SQL against the target instance using the connected user's security context. The research demonstrates that an attacker who can influence Copilot's behavior — for example through a maliciously crafted database object, poisoned schema metadata, or prompt-injection content embedded in data the assistant reads — can cause Copilot to generate and run statements the user never intended. Because of the underlying SQL Server authorization flaw, this chain results in the session gaining privileges far beyond what it was granted, up to and including membership in the sysadmin fixed server role.
From a SOC perspective, the observable attack chain looks like this:
- Attacker (or a compromised low-privilege account) connects to SQL Server via SSMS with Copilot enabled.
- Copilot processes attacker-influenced context (schema names, comments, stored procedure text, or data) and emits malicious T-SQL.
- The generated statements execute in-session — expect artifacts such as
ALTER SERVER ROLE sysadmin ADD MEMBER,sp_addsrvrolemember, or creation of new logins. - With sysadmin obtained, the full post-exploitation playbook opens: enabling
xp_cmdshell, spawning OS commands fromsqlservr.exe, deploying CLR assemblies, and pivoting to the host and domain.
Exploitation status
The vulnerability was disclosed through coordinated research presented at BlueHat Asia 2026, and Microsoft has shipped security updates. Public technical details and proof-of-concept material are now available alongside the talk write-up, which historically compresses the time-to-exploitation window dramatically. Assume active exploitation attempts will follow quickly. At time of writing there is no confirmed CISA KEV listing, but a Critical-rated, remotely leverageable privilege escalation in SQL Server should be treated with KEV-level urgency in your patch cycle.
Detection & Response
Patching is the primary control, but you must also hunt for pre-patch exploitation. Focus telemetry on three observable behaviors: (1) unexpected privilege grants in SQL Server, (2) sqlservr.exe spawning child processes (post-exploitation), and (3) SSMS processes behaving like automation or spawning shells.
Sigma Rules
---
title: SQL Server Process Spawning Command Shell or Scripting Engine
id: 3f8a2c71-9b4d-4e6a-a1c2-7d5e9f0b3a41
status: experimental
description: Detects sqlservr.exe spawning cmd, PowerShell, or other scripting hosts, consistent with post-exploitation after SQL Server privilege escalation (e.g., xp_cmdshell abuse following CVE-2026-65669 exploitation).
references:
- https://embracethered.com/blog/posts/2026/from-select-to-sysadmin-sql-copilot-bluehat-asia/
- https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.execution
- attack.t1059
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith: '\sqlservr.exe'
selection_child:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\rundll32.exe'
- '\regsvr32.exe'
- '\mshta.exe'
- '\certutil.exe'
- '\bitsadmin.exe'
condition: selection_parent and selection_child
falsepositives:
- Legitimate SQL Server maintenance jobs invoking command-line steps (rare on hardened systems)
level: high
---
title: SSMS or Copilot-Hosted Process Spawning Shell or Script Interpreter
id: 8c1d4e52-2a7f-4b93-9d6e-1f3a5c7e9b02
status: experimental
description: Detects SQL Server Management Studio or its child components spawning command shells or script interpreters, which may indicate AI-assisted execution of attacker-influenced commands related to CVE-2026-65669.
references:
- https://embracethered.com/blog/posts/2026/from-select-to-sysadmin-sql-copilot-bluehat-asia/
- https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.execution
- attack.t1059.001
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\Ssms.exe'
- '\SQLManagementStudio.exe'
selection_child:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
condition: selection_parent and selection_child
falsepositives:
- Administrators launching external tools from SSMS (uncommon; investigate all hits)
level: high
---
title: SQL Server Role Escalation Statement via Command-Line SQL Clients
id: 5e7b9d14-6c3a-4f81-8e2b-9a4d6f1c3e57
status: experimental
description: Detects command-line SQL clients (sqlcmd, osql) executing server-role privilege grant statements, a hallmark of SQL Server privilege escalation such as that enabled by CVE-2026-65669.
references:
- https://embracethered.com/blog/posts/2026/from-select-to-sysadmin-sql-copilot-bluehat-asia/
- https://attack.mitre.org/techniques/T1078/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.privilege_escalation
- attack.t1078
logsource:
category: process_creation
product: windows
detection:
selection_tool:
Image|endswith:
- '\sqlcmd.exe'
- '\osql.exe'
selection_cmd:
CommandLine|contains:
- 'ALTER SERVER ROLE'
- 'sysadmin ADD MEMBER'
- 'sp_addsrvrolemember'
- 'xp_cmdshell'
condition: selection_tool and selection_cmd
falsepositives:
- DBA provisioning scripts during onboarding; whitelist known automation accounts and hosts
level: high
KQL — Microsoft Sentinel / Defender
The first query hunts endpoint telemetry for the post-exploitation process chain. The second hunts SQL Server audit events (Event ID 33205, ingested via the SQL Server audit connector or Windows Security Event collection) for unauthorized role grants — this is the highest-fidelity signal that the CVE-2026-65669 chain completed.
// Hunt 1: sqlservr.exe spawning shells or LOLBins (post-exploitation after privilege escalation)
DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where InitiatingProcessFileName =~ "sqlservr.exe"
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe", "wscript.exe", "cscript.exe", "rundll32.exe", "regsvr32.exe", "mshta.exe", "certutil.exe", "bitsadmin.exe")
| project TimeGenerated, DeviceName, AccountName, InitiatingProcessFileName, FileName, ProcessCommandLine, SHA256, ReportId
| order by TimeGenerated desc;
// Hunt 2: SQL Server audit events for sysadmin grants, new logins, or dangerous configuration changes
// Requires SQL Server Audit / Windows application event forwarding (Event ID 33205) into Sentinel
SecurityEvent
| where TimeGenerated > ago(30d)
| where EventID == 33205
| where Statement has_any ("ALTER SERVER ROLE", "sp_addsrvrolemember", "sysadmin", "CREATE LOGIN", "xp_cmdshell", "sp_configure")
| extend StatementText = tostring(Statement)
| project TimeGenerated, Computer, SubjectUserName, ServerInstanceName, DatabaseName, StatementText
| order by TimeGenerated desc;
// Hunt 3: SSMS spawning unexpected child processes (Copilot-driven execution artifact)
DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where InitiatingProcessFileName in~ ("Ssms.exe", "SQLManagementStudio.exe")
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe", "wscript.exe", "cscript.exe")
| project TimeGenerated, DeviceName, AccountName, InitiatingProcessFileName, FileName, ProcessCommandLine, ReportId
| order by TimeGenerated desc;
Velociraptor VQL
This artifact performs two functions in a single hunt: it enumerates installed SSMS versions for patch-state verification across the fleet, and it captures any live sqlservr.exe child processes that match the post-exploitation pattern.
-- CVE-2026-65669 hunt: SSMS version inventory + sqlservr.exe child process detection
-- 1) Enumerate installed SQL Server Management Studio versions from uninstall registry keys
SELECT Name, DisplayName, DisplayVersion, Publisher
FROM read_reg_key(globs='HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\*',
accessor='registry')
WHERE DisplayName =~ 'SQL Server Management Studio'
-- 2) Identify sqlservr.exe processes and flag suspicious children
SELECT Pid, Ppid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE Name =~ '(?i)cmd\.exe|powershell\.exe|pwsh\.exe|wscript\.exe|cscript\.exe|rundll32\.exe|mshta\.exe|certutil\.exe'
AND Ppid IN (
SELECT Pid FROM pslist() WHERE Name =~ '(?i)sqlservr\.exe'
)
For deeper forensics on a suspect host, also collect the SSMS user profile and Copilot-related artifacts under %LOCALAPPDATA%\Microsoft\SQL Server Management Studio\ and the SQL Server default audit/error log directories (C:\Program Files\Microsoft SQL Server\MSSQL*\MSSQL\Log\) to reconstruct executed statements around the time of a role grant.
Remediation Verification & Hardening Script
# CVE-2026-65669 - SSMS Copilot / SQL Server privilege escalation: verify, harden, audit
# Run elevated on database hosts and admin workstations.
# 1) Inventory installed SSMS versions (Copilot-capable builds are SSMS 21.x)
Write-Host "=== Installed SSMS Versions ===" -ForegroundColor Cyan
$uninstallPaths = @(
'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*'
)
Get-ItemProperty $uninstallPaths -ErrorAction SilentlyContinue |
Where-Object { $_.DisplayName -like '*SQL Server Management Studio*' } |
Select-Object DisplayName, DisplayVersion, InstallDate | Format-Table -AutoSize
Write-Host "ACTION REQUIRED: Update SSMS to the latest patched release per the Microsoft CVE-2026-65669 advisory." -ForegroundColor Yellow
# 2) Inventory SQL Server instances and current build levels (patch-state check)
Write-Host "=== SQL Server Instances and Builds ===" -ForegroundColor Cyan
Get-Service | Where-Object { $_.Name -like 'MSSQL*' -and $_.Status -eq 'Running' } |
Select-Object Name, DisplayName | Format-Table -AutoSize
$instances = (Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Microsoft SQL Server\Instance Names\SQL' -ErrorAction SilentlyContinue).PSObject.Properties
foreach ($i in $instances) {
$ver = (Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Microsoft SQL Server\$($i.Value)\MSSQLServer\CurrentVersion" -ErrorAction SilentlyContinue).CurrentVersion
Write-Host "Instance: $($i.Name) Build: $ver -> Verify against the fixed build listed in Microsoft's CVE-2026-65669 advisory."
}
# 3) Disable Copilot in SSMS until patched (defense-in-depth)
Write-Host "=== Disabling Copilot in SSMS (per-user setting) ===" -ForegroundColor Cyan
$copilotKey = 'HKCU:\Software\Microsoft\SQL Server Management Studio\21.0\Copilot'
if (-not (Test-Path $copilotKey)) { New-Item -Path $copilotKey -Force | Out-Null }
Set-ItemProperty -Path $copilotKey -Name 'Enabled' -Value 0 -Type DWord
Write-Host "Copilot disabled for current user. Re-enable only after SSMS is patched." -ForegroundColor Yellow
# 4) Audit current sysadmin role membership for unauthorized principals
Write-Host "=== Current sysadmin Role Members (review for unauthorized accounts) ===" -ForegroundColor Cyan
$auditQuery = @"
SELECT sp.name AS LoginName, sp.type_desc AS LoginType, sp.create_date, sp.modify_date
FROM sys.server_role_members rm
JOIN sys.server_principals r ON rm.role_principal_id = r.principal_id
JOIN sys.server_principals sp ON rm.member_principal_id = sp.principal_id
WHERE r.name = 'sysadmin';
"@
Get-Service | Where-Object { $_.Name -match '^MSSQL\$|^MSSQLSERVER$' -and $_.Status -eq 'Running' } | ForEach-Object {
$inst = if ($_.Name -eq 'MSSQLSERVER') { '.' } else { ".\$($_.Name -replace 'MSSQL\$','')" }
Write-Host "--- Instance: $inst ---"
try {
Invoke-Sqlcmd -ServerInstance $inst -Query $auditQuery -TrustServerCertificate -ErrorAction Stop |
Format-Table -AutoSize
} catch { Write-Host "Query failed on $inst : $_" -ForegroundColor Red }
}
# 5) Enable SQL Server Audit for role membership changes going forward (if not already covered by SIEM)
Write-Host "=== Ensure SQL Server Audit captures SERVER_ROLE_MEMBER_CHANGE_GROUP and xp_cmdshell usage ===" -ForegroundColor Cyan
Write-Host "Forward Windows Application Event ID 33205 to your SIEM for detection rule coverage." -ForegroundColor Yellow
Remediation
- Patch immediately. Apply the Microsoft security update addressing CVE-2026-65669 to all affected SQL Server instances, and update SQL Server Management Studio to the latest release. Consult the Microsoft Security Response Center advisory for CVE-2026-65669 (https://msrc.microsoft.com) for the exact fixed builds per SQL Server version. Given the Critical rating and public technical disclosure, treat this as an emergency change window, not a routine monthly patch.
- Disable Copilot in SSMS until patched. Where immediate patching is not feasible, disable the Copilot feature (via SSMS settings/registry as shown above or via Group Policy/MDM on admin workstations). Copilot is the exposure surface; removing it removes the practical attack path while the underlying fix is deployed.
- Enforce least privilege on SQL Server. Audit every login with
sysadmin,securityadmin, orCONTROL SERVER. The pre-condition for this attack is a foothold with database access — minimize which accounts can connect interactively via SSMS, and prohibit shared SQL logins. - Enable and forward SQL Server Audit. Ensure audit specifications capture
SERVER_ROLE_MEMBER_CHANGE_GROUP,LOGIN_CHANGE_PASSWORD_GROUP,SCHEMA_OBJECT_CHANGE_GROUP, andsp_configure/xp_cmdshellexecution. Forward to your SIEM (Event ID 33205) so the KQL hunts above have data. - Hunt retroactively. Run the Sigma, KQL, and VQL content in this post against at least the last 30 days of telemetry. Any
ALTER SERVER ROLE sysadmin ADD MEMBERevent, unexpected sysadmin login created or modified recently, orsqlservr.exechild process is a full incident-response trigger. - Govern AI-assisted tooling. Add copilot/agent features in administrative consoles to your asset and risk register. Apply the same change-control, logging, and approval requirements you would to any automation executing privileged operations. This CVE will not be the last of its class.
If you find evidence of exploitation — unauthorized sysadmin membership, anomalous xp_cmdshell activity, or unexpected child processes of sqlservr.exe — isolate the host, preserve SQL Server error logs, audit logs, and SSMS artifacts, and engage your IR retainer before remediation wipes forensic evidence.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.