SQL injection in Microsoft SQL Server - CVE-2026-66820
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to improper neutralization of special elements used in an sql command in SQL Server when processing sql commands. A remote user can log in to the SQL Server with explicit permissions to elevate privileges.
Successful exploitation grants SQL sysadmin privileges.