Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft microsoft Sql Server 2017 (cu 31)
Microsoft microsoft Sql Server 2017 (gdr) Microsoft microsoft Sql Server 2019 (cu 32) Microsoft microsoft Sql Server 2019 (gdr) Microsoft microsoft Sql Server 2022 (cu 26) Microsoft microsoft Sql Server 2022 (gdr) Microsoft microsoft Sql Server 2025 (cu8) Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr) |
|
| Vendors & Products |
Microsoft microsoft Sql Server 2017 (cu 31)
Microsoft microsoft Sql Server 2017 (gdr) Microsoft microsoft Sql Server 2019 (cu 32) Microsoft microsoft Sql Server 2019 (gdr) Microsoft microsoft Sql Server 2022 (cu 26) Microsoft microsoft Sql Server 2022 (gdr) Microsoft microsoft Sql Server 2025 (cu8) Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr) |
Tue, 08 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network. | |
| Title | Microsoft SQL Server Elevation of Privilege Vulnerability | |
| First Time appeared |
Microsoft
Microsoft sql Server 2017 Microsoft sql Server 2019 Microsoft sql Server 2022 Microsoft sql Server 2025 |
|
| Weaknesses | CWE-1220 | |
| CPEs | cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:* cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:* cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:* cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:* |
|
| Vendors & Products |
Microsoft
Microsoft sql Server 2017 Microsoft sql Server 2019 Microsoft sql Server 2022 Microsoft sql Server 2025 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published: 2026-09-08T17:14:27.197Z
Updated: 2026-09-09T21:31:27.671Z
Reserved: 2026-07-27T19:02:26.601Z
Link: CVE-2026-66814
No data.
Status : Awaiting Analysis
Published: 2026-09-08T18:18:19.880
Modified: 2026-09-09T10:17:13.237
Link: CVE-2026-66814
No data.