Aug 2026: Azure SQL Managed Instance Elevation of Privilege Vulnerability
CVE-2026-62836 Published on August 6, 2026

Azure SQL Managed Instance Elevation of Privilege Vulnerability
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.

Vendor Advisory NVD

Weakness Type

Improper Restriction of Communication Channel to Intended Endpoints

The software establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.


Products Associated with CVE-2026-62836

Want to know whenever a new CVE is published for Microsoft Azure Sql Managed Instance? stack.watch will email you.

 

Affected Versions

Microsoft Azure SQL Managed Instance Version - is affected by CVE-2026-62836