Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-66818 Published on September 8, 2026

Microsoft SQL Server Elevation of Privilege Vulnerability
Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.

Vendor Advisory NVD

Weakness Type

Improper Privilege Management

The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.


Products Associated with CVE-2026-66818

Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.

 
 
 
 

Affected Versions

Microsoft SQL Server 2017 (CU 31): Microsoft SQL Server 2017 (GDR): Microsoft SQL Server 2019 (CU 32): Microsoft SQL Server 2019 (GDR): Microsoft SQL Server 2022 (CU 26): Microsoft SQL Server 2022 (GDR): Microsoft SQL Server 2025 (CU8): Microsoft SQL Server 2025 for x64-based Systems (GDR):