CVE-2026-66818
massNetwork-Reachable Privilege Escalation in Microsoft SQL Server
Microsoft SQL Server contains an improper privilege management flaw (CWE-269) that lets an authorized attacker gain more rights than their account should allow. The weakness is reachable over the network (AV:N), requires only low-level privileges (PR:L), and involves no user interaction, so any attacker holding valid low-privilege SQL Server credentials can trigger it remotely with crafted requests. Successful exploitation carries high impact for confidentiality, integrity and availability, meaning the attacker could read, modify or disrupt data while operating as a higher-privileged SQL Server principal. Any organization running Microsoft SQL Server is potentially affected, though the available data does not specify which version ranges are impacted, so administrators should check Microsoft's advisory for the affected and patched builds. No exploitation is known so far: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts the 30-day exploitation probability at roughly 0.6%.
What to do: Apply Microsoft's security update for CVE-2026-66818 once identified in the relevant Patch Tuesday release, verifying your exact SQL Server build numbers against the versions listed in the advisory. Until patched, restrict exposure of SQL Server ports (default TCP 1433) to trusted networks and review SQL Server logins for least privilege, since exploitation requires an authenticated account. Monitor Microsoft's advisory for updates on affected version ranges and watch public sources for emerging proof-of-concepts given the high severity score.
| Microsoft SQL Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.
- Vendors
- microsoft
- Products
- sql server 2017, sql server 2019, sql server 2022, sql server 2025
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.