Description
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Published: 2026-03-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Update
AI Analysis

Impact

The vulnerability results from improper neutralization of special elements in SQL commands, enabling an authorized attacker to perform SQL injection that elevates privileges over a network. Key detail from vendor description: "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network." This flaw, classified as CWE-89, lets an attacker with existing database access gain higher privileges, potentially compromising confidentiality, integrity, and availability of the database system.

Affected Systems

According to the CNA information, Microsoft SQL Server 2025 CU 2 and Microsoft SQL Server 2025 for x64-based systems (GDR) are affected. No other specific version information is provided in the data. The CPE list includes earlier SQL Server releases, but the vendor statement limits the impact to SQL Server 2025.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with the ability to submit SQL commands; the attacker can inject specially crafted input that is not properly sanitized, thereby elevating their privileges. The known attack vector is network‑based, relying on the attacker’s authorized database access.

Generated by OpenCVE AI on March 16, 2026 at 23:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Microsoft patch for SQL Server 2025 (CU 2 or newer).
  • If a patch cannot be applied immediately, disable or limit the privileges of accounts that have the ability to execute dynamic SQL.
  • Audit database users and enforce least‑privilege; monitor for abnormal query activity.

Generated by OpenCVE AI on March 16, 2026 at 23:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 13 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sql Server 2016
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
CPEs cpe:2.3:a:microsoft:sql_server_2016:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft sql Server 2016
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022

Tue, 10 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Mar 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Title SQL Server Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2025
Weaknesses CWE-89
CPEs cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sql Server 2016 Sql Server 2017 Sql Server 2019 Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-03-27T22:32:57.958Z

Reserved: 2026-02-11T15:52:13.910Z

Link: CVE-2026-26116

cve-icon Vulnrichment

Updated: 2026-03-10T17:51:07.592Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-10T18:18:40.827

Modified: 2026-03-13T20:14:30.767

Link: CVE-2026-26116

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-20T14:34:17Z

Weaknesses