Aug 2026: Azure SQL Database Elevation of Privilege Vulnerability
CVE-2026-66309 Published on August 20, 2026

Azure SQL Database Elevation of Privilege Vulnerability
Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

Vendor Advisory NVD

Weakness Type

What is an Authorization Vulnerability?

The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2026-66309 has been classified to as an Authorization vulnerability or weakness.


Products Associated with CVE-2026-66309

Want to know whenever a new CVE is published for Microsoft Azure Sql Database? stack.watch will email you.

 

Affected Versions

Microsoft Azure SQL Database Version - is affected by CVE-2026-66309