Improper Neutralization of Special Elements in Output Used by a Downstream Component in Microsoft SQL Server Management Studio - CVE-2026-65669
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to improper neutralization of special elements in output used by a downstream component in SQL Server. A remote attacker can trick a victim to submit specially crafted instructions to SQL Copilot in SQL Server Management Studio and gain elevated privileges on the target system.