Insufficient Granularity of Access Control in Microsoft SQL Server - CVE-2026-77480

 

Insufficient Granularity of Access Control in Microsoft SQL Server - CVE-2026-77480

Published: September 9, 2026


Vulnerability identifier: #VU148412
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-77480
CWE-ID: CWE-1220
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to elevate privileges to SQL sysadmin privileges.

The vulnerability exists due to insufficient granularity of access control in SQL Server when logging in to the SQL Server with explicit permissions. A remote user can log in to the SQL Server and elevate privileges to SQL sysadmin.


Affected software

Microsoft SQL Server

How to mitigate CVE-2026-77480

Install security update from vendor's website.

Microsoft SQL Server - addressed in versions 14.0.2130.4, 14.0.3550.4, 15.0.2190.7, 15.0.4490.9, 16.0.1200.5, 16.0.4275.2, 17.0.1135.8, 17.0.4085.5

External References

Related Security Bulletins