Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-77480 Published on September 8, 2026

SQL Server Elevation of Privilege Vulnerability
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Vendor Advisory NVD

Weakness Type

Insufficient Granularity of Access Control

The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.


Products Associated with CVE-2026-77480

Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.

 
 
 
 

Affected Versions

Microsoft SQL Server 2017 (CU 31): Microsoft SQL Server 2017 (GDR): Microsoft SQL Server 2019 (CU 32): Microsoft SQL Server 2019 (GDR): Microsoft SQL Server 2022 (CU 26): Microsoft SQL Server 2022 (GDR): Microsoft SQL Server 2025 (CU8): Microsoft SQL Server 2025 for x64-based Systems (GDR):