Description
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-08-06
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from improper restriction of the communication channel to intended endpoints in Azure SQL Managed Instance, enabling an attacker who can reach the instance over the network to elevate privileges. The flaw allows a non‑privileged user to gain higher privileges within the managed instance, potentially compromising database contents and other resources that rely on the instance. The underlying weakness corresponds to CWE‑923, which covers improper restrictions in a communication channel that allow an attacker to perform unauthorized actions.

Affected Systems

The affected product is Microsoft Azure SQL Managed Instance, as identified by the CNA vendor and product name. No specific version information is provided in the CNA data, so any instance of Azure SQL Managed Instance that has not been patched according to the Microsoft Security Response Center guidance is considered vulnerable.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity of this flaw. The EPSS score is not available, so the current likelihood of exploitation cannot be quantified, but the absence of a patch limits remedial options. This vulnerability is not listed in the CISA KEV catalog. Based on the description, the attacker must be able to communicate with the Azure SQL Managed Instance over the network; thus the likely attack vector is a network-based privilege escalation. No conditions such as local user access or specific software execution are indicated, implying that remote attackers with network access may exploit the flaw if no mitigations are in place.

Generated by OpenCVE AI on August 7, 2026 at 01:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft security update for Azure SQL Managed Instance as published on the Microsoft Security Response Center.
  • Configure network-level restrictions, such as firewall rules or private endpoints, to limit inbound connections to the instance to trusted clients only.
  • Enable and review audit logging and threat detection for Azure SQL Managed Instance to identify any abnormal privilege‑escalation activity.

Generated by OpenCVE AI on August 7, 2026 at 01:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
Title Azure SQL Managed Instance Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft azure Sql Managed Instance
Weaknesses CWE-923
CPEs cpe:2.3:a:microsoft:azure_sql_managed_instance:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Sql Managed Instance
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Sql Managed Instance
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-29T16:20:56.315Z

Reserved: 2026-07-14T21:10:38.083Z

Link: CVE-2026-62836

cve-icon Vulnrichment

Updated: 2026-08-07T14:52:42.095Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-07T00:16:34.727

Modified: 2026-08-12T05:18:52.430

Link: CVE-2026-62836

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:58:37Z

Weaknesses
  • CWE-923

    Improper Restriction of Communication Channel to Intended Endpoints