Description
Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-08
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Elevation of Privilege
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is an improper neutralization of special elements in output that is subsequently consumed by a downstream component. The flaw enables an attacker who can influence that output to inject malicious content, resulting in elevation of privileges on the target SQL Server. The impact manifests as the attacker gaining higher-level permissions than intended.

Affected Systems

The affected software is Microsoft SQL Server Management Studio version 22. Only this specific product and version are mentioned as vulnerable; other versions of SQL Server Management Studio are not listed as affected.

Risk and Exploitability

The CVSS score of 9.6 indicates a critical severity, emphasizing the high potential for privilege escalation. No EPSS score is available, so the current exploitation probability is unknown, but the absence of a KEV listing does not negate the risk. Given the network‑based nature implied by the ability to deliver the exploited output over a network, the likely attack vector is remote exploitation from an application or service that interacts with the vulnerable component.

Generated by OpenCVE AI on September 8, 2026 at 19:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft security update for SQL Server Management Studio 22 available from the Microsoft Update guide.
  • Verify that any custom or third‑party modules generating output for downstream processing properly escape or sanitize special characters according to standard input validation practices.
  • If an immediate patch cannot be applied, limit the exposed functionality or restrict network access to the vulnerable component, and monitor for unauthorized privilege escalation.

Generated by OpenCVE AI on September 8, 2026 at 19:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.
Title Microsoft SQL Server Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft sql Server Management Studio
Weaknesses CWE-74
CPEs cpe:2.3:a:microsoft:sql_server_management_studio:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sql Server Management Studio
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sql Server Management Studio
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:33:45.623Z

Reserved: 2026-07-22T18:16:01.897Z

Link: CVE-2026-65669

cve-icon Vulnrichment

Updated: 2026-09-09T10:00:13.361Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:18:14.893

Modified: 2026-09-09T10:17:11.290

Link: CVE-2026-65669

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:00:12Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')