Insufficient Granularity of Access Control in Microsoft SQL Server - CVE-2026-77480
Published: September 9, 2026
Vulnerability identifier: #VU148412
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-77480
CWE-ID: CWE-1220
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to elevate privileges to SQL sysadmin privileges.
The vulnerability exists due to insufficient granularity of access control in SQL Server when logging in to the SQL Server with explicit permissions. A remote user can log in to the SQL Server and elevate privileges to SQL sysadmin.
Affected software
Microsoft SQL Server
How to mitigate CVE-2026-77480
Install security update from vendor's website.
Microsoft SQL Server - addressed in versions 14.0.2130.4, 14.0.3550.4, 15.0.2190.7, 15.0.4490.9, 16.0.1200.5, 16.0.4275.2, 17.0.1135.8, 17.0.4085.5