Insufficient Granularity of Access Control in Microsoft SQL Server - CVE-2026-66814

 

Insufficient Granularity of Access Control in Microsoft SQL Server - CVE-2026-66814

Published: September 9, 2026


Vulnerability identifier: #VU148362
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-66814
CWE-ID: CWE-1220
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to elevate privileges.

The vulnerability exists due to insufficient granularity of access control in SQL Server when processing a login from a user with explicit permissions. A remote user can log in to the SQL Server and elevate their privileges to SQL sysadmin.

Exploitation requires explicit permissions on the SQL Server.


Affected software

Microsoft SQL Server

How to mitigate CVE-2026-66814

Install security update from vendor's website.

Microsoft SQL Server - addressed in versions 14.0.2130.4, 14.0.3550.4, 15.0.2190.7, 15.0.4490.9, 16.0.1200.5, 16.0.4275.2, 17.0.1135.8, 17.0.4085.5

External References

Related Security Bulletins