SQL injection in Microsoft SQL Server - CVE-2026-66819
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to improper neutralization of special elements used in an SQL command in SQL Server when processing SQL commands. A remote user can log in to the SQL Server and exploit SQL injection to elevate privileges.
Successful exploitation grants SQL sysadmin privileges.