ZeroHour

CVE-2026-73028

mass

Privilege Escalation via Improper Access Control in Microsoft SQL Server

CVSS 3.1
8.8 high
EPSS
<1%p44
Published
()
Modified
AI analysis

CVE-2026-73028 is an improper access control flaw (CWE-284) in Microsoft SQL Server that allows an authorized attacker to elevate privileges. It is exploited over the network: a low-privileged, already-authenticated user can trigger it remotely with low attack complexity and no user interaction. A successful attacker gains high impact to confidentiality, integrity, and availability, effectively acting with elevated privileges within the database environment. Any organization running an affected Microsoft SQL Server build is affected, though the specific version ranges are not provided in the available data. There is no evidence of active exploitation: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates only a 0.5% probability of exploitation within 30 days.

What to do: Check Microsoft's advisory for CVE-2026-73028 to determine which SQL Server versions are affected and apply the corresponding security update. Until patched, limit which low-privileged accounts can reach SQL Server over the network and review remote access permissions for database roles. Watch for updates to CISA KEV and EPSS, as any escalation in exploitation status warrants prioritizing the patch.

Affected
Microsoft SQL Server
Estimated exposure
massmillions of installations worldwide (SQL Server's global installed base) — Microsoft SQL Server is one of the most widely deployed database platforms, running on millions of servers and instances across enterprise and cloud environments per public market-share surveys, although the affected version ranges are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Vendors
microsoft
Products
sql server 2017, sql server 2019, sql server 2022, sql server 2025
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.