CVE-2026-73028
massPrivilege Escalation via Improper Access Control in Microsoft SQL Server
CVE-2026-73028 is an improper access control flaw (CWE-284) in Microsoft SQL Server that allows an authorized attacker to elevate privileges. It is exploited over the network: a low-privileged, already-authenticated user can trigger it remotely with low attack complexity and no user interaction. A successful attacker gains high impact to confidentiality, integrity, and availability, effectively acting with elevated privileges within the database environment. Any organization running an affected Microsoft SQL Server build is affected, though the specific version ranges are not provided in the available data. There is no evidence of active exploitation: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates only a 0.5% probability of exploitation within 30 days.
What to do: Check Microsoft's advisory for CVE-2026-73028 to determine which SQL Server versions are affected and apply the corresponding security update. Until patched, limit which low-privileged accounts can reach SQL Server over the network and review remote access permissions for database roles. Watch for updates to CISA KEV and EPSS, as any escalation in exploitation status warrants prioritizing the patch.
| Microsoft SQL Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
- Vendors
- microsoft
- Products
- sql server 2017, sql server 2019, sql server 2022, sql server 2025
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.