Description
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to elevate privileges locally.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This SQL injection flaw arises from improper neutralization of special elements in an SQL command used by Microsoft Entra Connect Sync. Because the component executes unsanitized input, an authorized user can inject arbitrary SQL statements, ultimately allowing local privilege elevation within the Entra Connect installation. The increased privileges could enable the attacker to view or alter identity data and configuration settings, potentially compromising subsequent authentication and authorization processes that rely on Entra Connect.

Affected Systems

The affected product is Microsoft Entra Connect. No specific vulnerable version information is provided. The guidance should be applied to all installations of Entra Connect that have not yet been patched to the latest release.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity risk, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, implying that no confirmed widespread exploitation has been reported yet. Based on the nature of the flaw (CWE-89) and the fact that Entra Connect typically runs with administrative privileges on the host, the likely attack vector is via local or remote access to the management interface that submits data to the vulnerable component.

Generated by OpenCVE AI on August 13, 2026 at 01:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Entra Connect security update from the official Microsoft update portal
  • Restrict access to the Entra Connect management interface to trusted network segments and authenticated administrators only
  • Configure firewalls to allow only the required traffic ports for Entra Connect and block any unnecessary inbound connections
  • Enable detailed audit logging for database operations and monitor for anomalous SQL queries that could indicate exploitation attempts

Generated by OpenCVE AI on August 13, 2026 at 01:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft entra Connect
CPEs cpe:2.3:a:microsoft:entra_connect:*:*:*:*:*:*:*:*
Vendors & Products Microsoft entra Connect

Wed, 12 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description Entra Connect Elevation of Privilege Vulnerability Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to elevate privileges locally.

Wed, 12 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description CVET-EOP Entra Connect Elevation of Privilege Vulnerability

Tue, 11 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Description Entra Connect Elevation of Privilege Vulnerability CVET-EOP

Tue, 11 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Description CVET-EOP Entra Connect Elevation of Privilege Vulnerability

Tue, 11 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Entra Connect Elevation of Privilege Vulnerability CVET-EOP

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description CVET-EOP Entra Connect Elevation of Privilege Vulnerability
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description Entra Connect Elevation of Privilege Vulnerability CVET-EOP

Tue, 11 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Description CVET-EOP Entra Connect Elevation of Privilege Vulnerability

Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description CVET-EOP
Title Microsoft Entra Connect Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft microsoft Entra Connect
Weaknesses CWE-89
CPEs cpe:2.3:a:microsoft:microsoft_entra_connect:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft microsoft Entra Connect
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Entra Connect Microsoft Entra Connect
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:07:33.942Z

Reserved: 2026-07-22T18:16:01.898Z

Link: CVE-2026-65673

cve-icon Vulnrichment

Updated: 2026-08-11T18:54:54.245Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:55.303

Modified: 2026-08-17T14:42:49.713

Link: CVE-2026-65673

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:31:15Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')