ZeroHour

CVE-2026-66818

mass

Network-Reachable Privilege Escalation in Microsoft SQL Server

CVSS 3.1
8.8 high
EPSS
<1%p46
Published
()
Modified
AI analysis

Microsoft SQL Server contains an improper privilege management flaw (CWE-269) that lets an authorized attacker gain more rights than their account should allow. The weakness is reachable over the network (AV:N), requires only low-level privileges (PR:L), and involves no user interaction, so any attacker holding valid low-privilege SQL Server credentials can trigger it remotely with crafted requests. Successful exploitation carries high impact for confidentiality, integrity and availability, meaning the attacker could read, modify or disrupt data while operating as a higher-privileged SQL Server principal. Any organization running Microsoft SQL Server is potentially affected, though the available data does not specify which version ranges are impacted, so administrators should check Microsoft's advisory for the affected and patched builds. No exploitation is known so far: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts the 30-day exploitation probability at roughly 0.6%.

What to do: Apply Microsoft's security update for CVE-2026-66818 once identified in the relevant Patch Tuesday release, verifying your exact SQL Server build numbers against the versions listed in the advisory. Until patched, restrict exposure of SQL Server ports (default TCP 1433) to trusted networks and review SQL Server logins for least privilege, since exploitation requires an authenticated account. Monitor Microsoft's advisory for updates on affected version ranges and watch public sources for emerging proof-of-concepts given the high severity score.

Affected
Microsoft SQL Server
Estimated exposure
masson the order of millions of SQL Server instances deployed worldwide, with hundreds of thousands of SQL Server services exposed to the public internet per… — SQL Server consistently ranks among the most widely deployed enterprise relational databases by market share, and internet-wide scan services routinely report hundreds of thousands of exposed SQL Server endpoints; because Microsoft has not…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.

Vendors
microsoft
Products
sql server 2017, sql server 2019, sql server 2022, sql server 2025
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.