Description
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is an improper access control flaw (CWE‑284) that allows an attacker who already has network access to a SQL Server instance to elevate their privileges and perform actions normally restricted to higher‑level users.

Affected Systems

Affected products are Microsoft SQL Server 2017 CU 31 and GDR, SQL Server 2019 CU 32 and GDR, SQL Server 2022 CU 26 and GDR, and SQL Server 2025 CU 8 along with its GDR for 64‑bit systems.

Risk and Exploitability

The flaw carries a CVSS score of 8.8, placing it in the high‑severity range. Exploitation requires an authenticated attacker with access to the SQL Server network interface, so the attack vector is most likely over a network connection to the server. The EPSS score is not available and the vulnerability is not listed in CISA KEV, indicating no publicly known exploits at this time, yet the high impact warrants prompt attention.

Generated by OpenCVE AI on September 9, 2026 at 02:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft SQL Server security update that resolves CVE‑2026‑77487 (download from the Microsoft Security Response Center update guide).
  • Restrict network access to SQL Server by enforcing the principle of least privilege, limiting authenticated users to those who truly require connectivity until the patch is in place.
  • Review and reduce high‑privilege accounts: audit current user permissions and remove any unnecessary elevated privileges to minimize potential damage if privilege escalation succeeds.

Generated by OpenCVE AI on September 9, 2026 at 02:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Sql Server 2017 (cu 31)
Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (cu 32)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 (cu 2)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)
Vendors & Products Microsoft microsoft Sql Server 2017 (cu 31)
Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (cu 32)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 (cu 2)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Title SQL Server Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
Weaknesses CWE-284
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Microsoft Sql Server 2017 (cu 31) Microsoft Sql Server 2017 (gdr) Microsoft Sql Server 2019 (cu 32) Microsoft Sql Server 2019 (gdr) Microsoft Sql Server 2022 (gdr) Microsoft Sql Server 2025 (cu 2) Microsoft Sql Server 2025 For X64-based Systems (gdr) Sql Server 2017 Sql Server 2019 Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:01.362Z

Reserved: 2026-08-20T20:11:33.672Z

Link: CVE-2026-77487

cve-icon Vulnrichment

Updated: 2026-09-08T19:24:56.403Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:34.397

Modified: 2026-09-15T15:43:50.457

Link: CVE-2026-77487

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:49:02Z

Weaknesses