Insufficient Granularity of Access Control in Microsoft SQL Server - CVE-2026-66814
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to insufficient granularity of access control in SQL Server when processing a login from a user with explicit permissions. A remote user can log in to the SQL Server and elevate their privileges to SQL sysadmin.
Exploitation requires explicit permissions on the SQL Server.