SSMS 22's Copilot could be talked out of read-only: CVE-2026-65669 was fixed in 22.8.2, six weeks before the advisory
CVE-2026-65669 let crafted instructions push Copilot in SSMS 22 past its read-only limits with the connected user's permissions, and Microsoft's own docs say what the real boundary is.
Microsoft's September 8 security release included a Critical-rated flaw in the AI assistant built into SQL Server Management Studio 22. CVE-2026-65669 carries a CVSS 3.1 base score of 9.6, and its FAQ describes the problem in two sentences that anyone who has let an assistant near a production database will recognize.
What the advisory says
The Security Update Guide entry is titled "Microsoft SQL Server Elevation of Privilege Vulnerability" and classifies the bug as CWE-74, injection. The only affected product listed is SQL Server Management Studio 22; the server engine itself is not. The FAQ reads:
An attacker could convince a user to submit specially crafted instructions to SQL Copilot in SQL Server Management Studio. Successful exploitation could bypass intended read-only restrictions and allow database data to be accessed or modified using the connected user's permissions.
Microsoft Security Response Center, CVE-2026-65669
The vector string is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H. Two parts matter for triage. UI:R means a user has to submit the instructions; Microsoft's FAQ adds "User interaction is required." S:C (scope changed) is what pushes a user-assisted bug to 9.6: the damage lands in the database, outside the client where the bug lives. Microsoft marks it not publicly disclosed, not exploited, and "Exploitation Less Likely."
The fix is older than the advisory
MSRC's affected-product record lists the remediation as a security update with fixed build number 22.8.2, and the CVE record at cve.org gives the affected range as version 22.0 up to, but not including, 22.8.2. The SSMS 22 release notes date 22.8.2 to July 28, 2026. That is 42 days before the September 8 disclosure. The CVE ID itself was reserved on July 22.
The 22.8.2 entry in those release notes says nothing about security. It lists a Visual Studio update to 18.8.2 and one bug fix under "GitHub Copilot in SSMS": inline chat failing with "There was a problem completing your request. Please try again." Other releases on the same page do name the CVEs they address.
The names do not line up either: the advisory says "SQL Copilot," while the release notes and Copilot documentation call the feature "GitHub Copilot in SSMS."
Which read-only restrictions
Microsoft's documentation describes two read-only behaviors. Ask mode's execution is listed as "Read-only queries only." Agent mode, a preview feature that requires SSMS 22.7 or later, has a separate setting: "By default, Agent mode is configured as READ_ONLY," and it can be switched to READ_WRITE in mcp.json. The advisory does not say which of these was bypassed. The affected range starts at 22.0, before Agent mode existed, but a CPE range alone does not prove that Ask mode was vulnerable.
What the documentation does say plainly is where the real boundary sits. The Agent mode page warns: "The security boundary is SQL Server's permission enforcement, not Copilot's approval system." The execution context page adds that "Copilot has no separate permissions and no elevated access." A client-side read-only mode is a guardrail, and CVE-2026-65669 is Microsoft confirming the model could be talked past it.
What to do
Update SSMS 22 to 22.8.2 or later. The current release on the notes page is 22.10.0, dated September 8. Beyond the patch, the documented controls that do not depend on the assistant behaving are the ones worth using:
- Run Copilot as a lesser account. Since SSMS 22.7, a database's
CONSTITUTION.mdextended property can setagentExecuteAsUser, and SSMS usesEXECUTE ASto run Copilot-generated queries under that identity. A reporting user withSELECTonly cannot modify data however it is prompted. - Remove Agent mode where it is not needed. Also since 22.7, a group policy under SQL Server Management Studio > Copilot Settings > Disable Agent Mode turns it off.
- Watch approval scope. Agent mode offers "Allow for this session" and "Allow always"; Microsoft itself says the approval prompt is not a security boundary.
The short version: the permission set of the login Copilot runs as is the permission set a crafted prompt can reach.
Primary sources: MSRC Security Update Guide, CVE-2026-65669, CVE record CVE-2026-65669, SSMS 22 release notes, GitHub Copilot Agent mode in SSMS, Execution context for GitHub Copilot in SSMS, Admin controls for GitHub Copilot in SSMS, read 2026-09-15.