Description
Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch
AI Analysis

Impact

The vulnerability is caused by improper privilege management in Microsoft SQL Server, allowing an attacker who already has authenticated access to the server to gain higher privileges over a network.

Affected Systems

Affected products include Microsoft SQL Server 2017 cumulative update 31 and the guaranteed delivery release, Microsoft SQL Server 2019 cumulative update 32 and the guaranteed delivery release, Microsoft SQL Server 2022 cumulative update 26 and the guaranteed delivery release, and Microsoft SQL Server 2025 cumulative update 8 and the guaranteed delivery release for x64‑based systems.

Risk and Exploitability

The CVSS base score of 8.8 classifies this issue as high severity. No EPSS score is available, so the current exploit probability is unknown; however, the vulnerability does not appear in the CISA KEV catalog, indicating no known active exploitation. The flaw requires an attacker to already possess authenticated access to a SQL Server instance, limiting the initial attack surface to environments where credentials are compromised or misused. Once that prerequisite is met, the attacker can elevate privileges, thereby compromising the security posture of affected databases.

Generated by OpenCVE AI on September 8, 2026 at 22:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest cumulative update for the affected SQL Server version from the Microsoft Security Response Center.
  • Restrict remote network access to the SQL Server instance and enforce least‑privilege account policies to limit the blast radius of credential compromise.
  • Conduct a security audit to verify correct privilege assignments and remove any unnecessary elevated accounts.

Generated by OpenCVE AI on September 8, 2026 at 22:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Sql Server 2017 (cu 31)
Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (cu 32)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (cu 26)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 (cu 8)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)
Vendors & Products Microsoft microsoft Sql Server 2017 (cu 31)
Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (cu 32)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (cu 26)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 (cu 8)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.
Title Microsoft SQL Server Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
Weaknesses CWE-269
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Microsoft Sql Server 2017 (cu 31) Microsoft Sql Server 2017 (gdr) Microsoft Sql Server 2019 (cu 32) Microsoft Sql Server 2019 (gdr) Microsoft Sql Server 2022 (cu 26) Microsoft Sql Server 2022 (gdr) Microsoft Sql Server 2025 (cu 8) Microsoft Sql Server 2025 For X64-based Systems (gdr) Sql Server 2017 Sql Server 2019 Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:34:18.087Z

Reserved: 2026-07-27T19:02:26.601Z

Link: CVE-2026-66818

cve-icon Vulnrichment

Updated: 2026-09-09T09:59:43.783Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:18:20.143

Modified: 2026-09-16T11:58:41.030

Link: CVE-2026-66818

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T22:15:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management