CVE-2026-77487
massAuthenticated Privilege Escalation in Microsoft SQL Server
Microsoft SQL Server contains an improper access control flaw (CWE-284) that allows an authorized, low-privileged user to elevate privileges over the network. Exploitation requires only existing low-level credentials and network reachability to the SQL Server instance; no user interaction or local access is needed (AV:N, PR:L, UI:N). An attacker who succeeds gains elevated privileges with high impact on confidentiality, integrity, and availability of the database (CVSS 3.1: 8.8 High). Organizations running Microsoft SQL Server are affected; the available data does not specify which versions or update levels are impacted, so defenders should consult Microsoft's advisory for affected-release details. As of this writing there is no known exploitation, no public proof-of-concept, and the flaw is not in the CISA KEV catalog, with EPSS estimating roughly a 0.5% probability of exploitation in the next 30 days (44th percentile).
What to do: Apply Microsoft's SQL Server security update for this CVE once published, using the version-specific guidance in the MSRC advisory, since affected version ranges are not specified in the available data. In the interim, restrict network exposure of SQL Server (especially TCP 1433 on internet-facing hosts), audit which low-privileged logins and accounts can connect to each instance, and enforce least-privilege role assignments. Prioritize patching instances that are reachable from untrusted networks or shared multi-tenant environments where low-privileged users exist.
| Microsoft SQL Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
- Vendors
- microsoft
- Products
- sql server 2017, sql server 2019, sql server 2022, sql server 2025
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.