Description
External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.
Published: 2026-07-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Microsoft SQL Server originates from external manipulation of file names or paths that the engine processes, a condition classified as CWE‑73. An attacker who has legitimate local user rights can supply a crafted file name or path, causing the server to treat that input as a higher‑privileged request and thereby elevate the attacker’s privileges to that of a higher‑level account. This privilege escalation can enable the attacker to execute arbitrary code, access or modify databases, and compromise data confidentiality, integrity, and availability.

Affected Systems

Affected products include Microsoft SQL Server 2016 Service Pack 3 and its GDR, the 2016 Service Pack 3 Azure Connect Feature Pack, SQL Server 2017 CU 31 and its GDR, SQL Server 2019 CU 32 and its GDR, SQL Server 2022 GDR and CU 25, and SQL Server 2025 CU 6 and its GDR – all 64‑bit Windows editions. The vulnerability exists in components that process file name or path input across these releases.

Risk and Exploitability

The CVSS score of 7.8 denotes high severity, while the EPSS score of less than 1 % indicates a low probability of widespread exploitation; the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local authorized access and the ability to supply a crafted file name or path, indicating that the attack vector is local privilege escalation rather than remote. Attack success depends on the attacker’s ability to influence the server’s file handling logic.

Generated by OpenCVE AI on July 31, 2026 at 09:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest cumulative security update for your Microsoft SQL Server version that addresses the file name/path validation flaw (refer to the MSRC update guide for CVE‑2026‑55002).
  • Restrict any application or user accounts that can supply arbitrary file names or paths to the database engine, ensuring such inputs are validated or sanitized before use.
  • Run the SQL Server service under a dedicated, least‑privileged local account and enforce the principle of least privilege on all Windows accounts that interact with the database, limiting the impact of any compromised account.

Generated by OpenCVE AI on July 31, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Description External control of file name or path in SQL Server allows an authorized attacker to elevate privileges locally. External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 15 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Sql Server 2016 Service Pack 3 (gdr)
Microsoft microsoft Sql Server 2016 Service Pack 3 Azure Connect Feature Pack
Microsoft microsoft Sql Server 2017 (cu 31)
Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (cu 32)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2022 For X64-based Systems (cu 23)
Microsoft microsoft Sql Server 2025 (cu 2)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)
Vendors & Products Microsoft microsoft Sql Server 2016 Service Pack 3 (gdr)
Microsoft microsoft Sql Server 2016 Service Pack 3 Azure Connect Feature Pack
Microsoft microsoft Sql Server 2017 (cu 31)
Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (cu 32)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2022 For X64-based Systems (cu 23)
Microsoft microsoft Sql Server 2025 (cu 2)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)

Tue, 14 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description External control of file name or path in SQL Server allows an authorized attacker to elevate privileges locally.
Title Microsoft SQL Server Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2016
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
Weaknesses CWE-73
CPEs cpe:2.3:a:microsoft:sql_server_2016:*:sp3:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2016
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Microsoft Sql Server 2016 Service Pack 3 (gdr) Microsoft Sql Server 2016 Service Pack 3 Azure Connect Feature Pack Microsoft Sql Server 2017 (cu 31) Microsoft Sql Server 2017 (gdr) Microsoft Sql Server 2019 (cu 32) Microsoft Sql Server 2019 (gdr) Microsoft Sql Server 2022 (gdr) Microsoft Sql Server 2022 For X64-based Systems (cu 23) Microsoft Sql Server 2025 (cu 2) Microsoft Sql Server 2025 For X64-based Systems (gdr) Sql Server 2016 Sql Server 2017 Sql Server 2019 Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:53:26.405Z

Reserved: 2026-06-16T14:10:05.869Z

Link: CVE-2026-55002

cve-icon Vulnrichment

Updated: 2026-07-14T17:40:17.469Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:30:05Z

Weaknesses
  • CWE-73

    External Control of File Name or Path