Description
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

An improper access control weakness in Microsoft SQL Server allows an attacker who already has legitimate access to the database to increase their privileges when communicating over a network. This flaw can enable a user with limited rights to obtain higher permissions, potentially giving them full control over the database instance and the underlying operating system if the SQL Server process has elevated rights. The CVSS score of 8.8 indicates a high severity, and although no EPSS value is available, the lack of a KEV listing suggests that the vulnerability has not yet been widely exploited in the wild, but the risk remains significant for any unpatched system

Affected Systems

Microsoft SQL Server 2017 cumulative update 31 and the GDR, Microsoft SQL Server 2019 cumulative update 32 and the GDR, Microsoft SQL Server 2022 cumulative update 26 and the GDR, and Microsoft SQL Server 2025 cumulative update 8 and the GDR, all for x64‑based systems

Risk and Exploitability

The weakness is identified as CWE‑284, an access control failure. The flaw can be exploited by a legitimate user who bypasses the intended permission checks to elevate rights over the network. The attack vector is inferred to be remote, as the description states “over a network.” The absence of an EPSS score provides no quantitative indication of exploitation probability, but the high CVSS score and the potential for complete compromise mean that the vulnerability should be treated with urgency. No KEV listing means the vulnerability has not been publicly confirmed to be exploited, yet the impact of compromise is severe if the flaw is leveraged.

Generated by OpenCVE AI on September 9, 2026 at 01:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest cumulative update and the GDR released by Microsoft for the affected SQL Server version
  • Enforce the principle of least privilege by reviewing and tightening the permissions granted to database accounts and network access controls
  • Validate that all applications and services accessing SQL Server are using role‑based access control consistent with the recommendations for CWE‑284

Generated by OpenCVE AI on September 9, 2026 at 01:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:*

Wed, 09 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Sql Server 2017 (cu 31)
Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (cu 32)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (cu 26)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 (cu8)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)
Vendors & Products Microsoft microsoft Sql Server 2017 (cu 31)
Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (cu 32)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (cu 26)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 (cu8)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Title SQL Server Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
Weaknesses CWE-284
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Microsoft Sql Server 2017 (cu 31) Microsoft Sql Server 2017 (gdr) Microsoft Sql Server 2019 (cu 32) Microsoft Sql Server 2019 (gdr) Microsoft Sql Server 2022 (cu 26) Microsoft Sql Server 2022 (gdr) Microsoft Sql Server 2025 (cu8) Microsoft Sql Server 2025 For X64-based Systems (gdr) Sql Server 2017 Sql Server 2019 Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:37:59.138Z

Reserved: 2026-08-10T18:43:43.200Z

Link: CVE-2026-73028

cve-icon Vulnrichment

Updated: 2026-09-09T09:53:49.388Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:32.830

Modified: 2026-09-15T16:11:56.950

Link: CVE-2026-73028

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T23:15:17Z

Weaknesses