Description
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Elevation of Privilege
Action: Immediate Patch
AI Analysis

Impact

Improper neutralization of special elements in a SQL command can lead to an SQL injection scenario that allows an attacker with legitimate access to the database to execute malicious queries and elevate their privileges. The vulnerability is rooted in CWE‑89, where insufficient input validation permits the injection of arbitrary SQL statements. An attacker who can send crafted requests over the network can potentially gain higher level permissions within the SQL Server instance, enabling them to read, modify or delete data, alter database schemas, or gain administrative access to the underlying operating system if backdoor access is available.

Affected Systems

Microsoft SQL Server 2017 (CU 31 and GDR), Microsoft SQL Server 2019 (CU 32 and GDR), Microsoft SQL Server 2022 (CU 26 and GDR), and Microsoft SQL Server 2025 (CU 8 and GDR) on x64‑based systems are all impacted by this flaw.

Risk and Exploitability

The flaw carries a CVSS score of 8.8, indicating high severity. An attacker who is already authenticated to the database or application can exploit this over a network connection, bypassing established role boundaries. EPSS data is currently unavailable, so the exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, suggesting no confirmed active exploits as of the latest data. Nonetheless, the potential for privilege escalation makes this a critical risk for organizations that rely on these SQL Server versions.

Generated by OpenCVE AI on September 8, 2026 at 19:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest cumulative update for Microsoft SQL Server from the official update guide (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67370) to remove the identified injection flaw.
  • Modify application code to use parameterized queries or stored procedures for all database interactions, ensuring that user-supplied data is never concatenated directly into SQL statements.
  • Implement the principle of least privilege in SQL Server by restricting user roles and reviewing permission grants, limiting the potential damage should an elevated privilege attack occur.

Generated by OpenCVE AI on September 8, 2026 at 19:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)
Vendors & Products Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Title Microsoft SQL Server Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
Weaknesses CWE-89
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Microsoft Sql Server 2017 (gdr) Microsoft Sql Server 2019 (gdr) Microsoft Sql Server 2022 (gdr) Microsoft Sql Server 2025 For X64-based Systems (gdr) Sql Server 2017 Sql Server 2019 Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:30:35.840Z

Reserved: 2026-07-29T14:57:03.840Z

Link: CVE-2026-67370

cve-icon Vulnrichment

Updated: 2026-09-09T10:04:47.919Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:18:20.817

Modified: 2026-09-16T12:01:45.920

Link: CVE-2026-67370

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T22:00:14Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')