ZeroHour

CVE-2026-66814

mass

Privilege Escalation in Microsoft SQL Server via Insufficient Access Control

CVSS 3.1
8.8 high
EPSS
<1%p36
Published
()
Modified
AI analysis

CVE-2026-66814 is a privilege-escalation vulnerability (CWE-1220, insufficient granularity of access control) in Microsoft SQL Server, rated 8.8 High with a network attack vector. A remote attacker who already holds a low-privileged, authorized account can send network requests to the database and, because access-control granularity is too coarse, obtain rights beyond those granted; no user interaction or special conditions are required. Successful exploitation carries high-impact consequences for confidentiality, integrity, and availability of the affected instance, effectively allowing the attacker to operate with elevated privileges. Any organization running an affected SQL Server build is exposed, especially where the database is reachable over the network by non-administrator accounts. Exploitation status is currently quiet: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns only a 0.4% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-66814 from Microsoft's advisory as soon as your SQL Server version branch is confirmed affected (version details were not included in this data). Until patched, restrict network access to SQL Server to trusted hosts and service accounts, and audit low-privileged logins for unexpected granted permissions or activity.

Affected
Microsoft SQL Server
Estimated exposure
masslikely millions of deployed instances; public internet scans show on the order of hundreds of thousands of exposed SQL Server endpoints — SQL Server is one of the most widely deployed relational databases in enterprise environments, and public internet-wide scans persistently report hundreds of thousands of reachable SQL Server instances, implying millions of total…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-1220
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.