I was in Italy for a month. While I was gone, somebody got sysadmin out of SQL Copilot with a variable.
The vulnerability is CVE-2026-65669, the SSMS 22 Copilot bug I wrote about early September. The full write-up went public on September 30th, and the detail that stuck with me is how Copilot’s ‘read-only mode’ was enforced. It wasn’t a permission. It was a regex blocklist.
That blocklist is the same control we have watched fail against SQL injection for twenty years. Before I get to Copilot, let’s build one here and see it fail.
These sorts of blacklists almost never work against a committed attacker because, unless you fully enumerate the possible domain, there’s an opportunity for someone to slip through, and that’s exactly what happened here.