SQL injection in Microsoft SQL Server - CVE-2026-66819

 

SQL injection in Microsoft SQL Server - CVE-2026-66819

Published: September 9, 2026


Vulnerability identifier: #VU148365
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-66819
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to elevate privileges.

The vulnerability exists due to improper neutralization of special elements used in an SQL command in SQL Server when processing SQL commands. A remote user can log in to the SQL Server and exploit SQL injection to elevate privileges.

Successful exploitation grants SQL sysadmin privileges.


Affected software

Microsoft SQL Server

How to mitigate CVE-2026-66819

Install security update from vendor's website.

Microsoft SQL Server - addressed in versions 14.0.2130.4, 14.0.3550.4, 15.0.2190.7, 15.0.4490.9, 16.0.1200.5, 16.0.4275.2, 17.0.1135.8, 17.0.4085.5

External References

Related Security Bulletins