Impact
An incorrect permission assignment for a critical resource in Azure SQL Database allows an authorized attacker with some existing subscription or user rights to elevate privileges locally. The flaw represents an authorization weakness (CWE‑732) that can enable a user to gain capabilities beyond what they were originally allowed.
Affected Systems
Microsoft Azure SQL Database is the affected product. No specific version information was listed, so any deployment of Azure SQL Database that is using the affected configuration is potentially impacted.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as high severity, indicating significant potential impact if exploited. The EPSS score is not available, so the likelihood of exploitation cannot be quantified from the public data. It is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. Attackers would likely need an authenticated, authorized session within Azure SQL Database to abuse the misconfigured permissions; the vulnerability does not appear to be directly exploitable by unauthenticated or remote actors.
OpenCVE Enrichment