Improper Neutralization of Special Elements in Output Used by a Downstream Component in Microsoft SQL Server Management Studio - CVE-2026-65669

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in Microsoft SQL Server Management Studio - CVE-2026-65669

Published: September 9, 2026


Vulnerability identifier: #VU148450
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-65669
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to improper neutralization of special elements in output used by a downstream component in SQL Server. A remote attacker can trick a victim to submit specially crafted instructions to SQL Copilot in SQL Server Management Studio and gain elevated privileges on the target system.


Affected software

Microsoft SQL Server Management Studio

How to mitigate CVE-2026-65669

Install updates from vendor's website.

Microsoft SQL Server Management Studio - update to 22.8.2

External References

Related Security Bulletins