CVE-2026-21262: SQL Server Elevation of Privilege Vulnerability
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Other sources
SQL Server Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4460.4Patch KB5077469 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1105.2Patch KB5077468 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3520.4Patch KB5077471 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4240.4Patch KB5077464 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.0.6480.4Patch KB5077474 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4020.2Patch KB5077466 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.0.7075.5Patch KB5077473 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1170.5Patch KB5077465 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2160.4Patch KB5077470 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2100.4Patch KB5077472
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21262?
CVE-2026-21262 has a high severity rating due to its potential for privilege escalation in SQL Server.
How do I fix CVE-2026-21262?
To fix CVE-2026-21262, update your SQL Server installation to the latest cumulative update provided by Microsoft.
Which versions of SQL Server are affected by CVE-2026-21262?
CVE-2026-21262 affects multiple versions of SQL Server including 2016, 2017, 2019, 2022 and future builds.
Can CVE-2026-21262 be exploited remotely?
Yes, CVE-2026-21262 can be exploited by an authorized attacker over a network.
Is there a known workaround for CVE-2026-21262?
There are no known workarounds for CVE-2026-21262; applying the appropriate security update is recommended.