CVE-2026-66814
massPrivilege Escalation in Microsoft SQL Server via Insufficient Access Control
CVE-2026-66814 is a privilege-escalation vulnerability (CWE-1220, insufficient granularity of access control) in Microsoft SQL Server, rated 8.8 High with a network attack vector. A remote attacker who already holds a low-privileged, authorized account can send network requests to the database and, because access-control granularity is too coarse, obtain rights beyond those granted; no user interaction or special conditions are required. Successful exploitation carries high-impact consequences for confidentiality, integrity, and availability of the affected instance, effectively allowing the attacker to operate with elevated privileges. Any organization running an affected SQL Server build is exposed, especially where the database is reachable over the network by non-administrator accounts. Exploitation status is currently quiet: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns only a 0.4% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-66814 from Microsoft's advisory as soon as your SQL Server version branch is confirmed affected (version details were not included in this data). Until patched, restrict network access to SQL Server to trusted hosts and service accounts, and audit low-privileged logins for unexpected granted permissions or activity.
| Microsoft SQL Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-1220
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.