CVE-2026-20803: Microsoft SQL Server Elevation of Privilege Vulnerability
Microsoft SQL Server Elevation of Privilege Vulnerability
Other sources
Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1050.2Patch KB5073177 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1165.1Patch KB5073031 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4230.2Patch KB5072936
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20803?
CVE-2026-20803 is considered a critical elevation of privilege vulnerability in Microsoft SQL Server.
How do I fix CVE-2026-20803?
To fix CVE-2026-20803, apply the latest security updates provided by Microsoft for affected SQL Server versions.
Which versions of SQL Server are affected by CVE-2026-20803?
CVE-2026-20803 affects Microsoft SQL Server 2022, SQL Server 2022 (CU 22), and SQL Server 2025.
What type of attack does CVE-2026-20803 facilitate?
CVE-2026-20803 allows an authorized attacker to elevate their privileges over a network.
Is there a workaround for CVE-2026-20803?
Currently, the best mitigation for CVE-2026-20803 is to apply the necessary updates since no specific workaround is available.