Description
Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
Published: 2026-07-02
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper access control in Azure Synapse enables an authorized attacker to elevate privileges across the network. The vulnerability is a CWE‑284 weakness where the service does not properly verify a user’s permissions. As a result, individuals with limited access can gain higher authority within Azure Synapse.

Affected Systems

All deployments of Microsoft Azure Synapse are potentially impacted because no specific version or configuration details are disclosed. The vulnerability applies wherever users have legitimate access to the Azure Synapse service, regardless of deployment size or setup.

Risk and Exploitability

The CVSS score of 4.8 indicates medium severity and the EPSS score of <1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is authentication‑based: an attacker who already has a valid Azure Synapse account can exploit the improper access control to elevate privileges. No additional prerequisites are explicitly stated. The impact is limited to resources that the elevated user can access within the Azure Synapse environment.

Generated by OpenCVE AI on August 12, 2026 at 01:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Azure Synapse update or patch published by Microsoft, as outlined in the MSRC advisory.
  • Ensure role assignments in Azure Synapse adhere to the principle of least privilege, removing any overly broad roles that could facilitate privilege escalation.
  • Implement network segmentation to isolate Azure Synapse resources from sensitive internal network areas, limiting potential lateral movement.

Generated by OpenCVE AI on August 12, 2026 at 01:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
Title Microsoft Azure Synapse Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft azure Synapse
Weaknesses CWE-284
CPEs cpe:2.3:a:microsoft:azure_synapse:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Synapse
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C'}


Subscriptions

Microsoft Azure Synapse
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:15:01.979Z

Reserved: 2026-02-11T16:24:51.134Z

Link: CVE-2026-26145

cve-icon Vulnrichment

Updated: 2026-07-06T11:55:58.735Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-02T23:16:49.813

Modified: 2026-07-07T14:27:00.440

Link: CVE-2026-26145

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T01:30:07Z

Weaknesses