CVE-2026-26115: SQL Server Elevation of Privilege Vulnerability
Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.
Other sources
SQL Server Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to Microsoft SQL Server to trusted hosts and management networks using firewall rules, network segmentation, or ACLs to reduce exposure to remote privilege escalation.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26115?
CVE-2026-26115 has been categorized as an elevation of privilege vulnerability.
How do I fix CVE-2026-26115?
To fix CVE-2026-26115, you should apply the relevant security updates or patches provided by Microsoft for affected SQL Server versions.
Which SQL Server versions are affected by CVE-2026-26115?
CVE-2026-26115 affects multiple SQL Server versions including 2016, 2017, 2019, 2022, and 2025.
Who is affected by CVE-2026-26115?
Any authorized user with access to the affected SQL Server versions may be able to exploit CVE-2026-26115 to elevate their privileges.
What are the potential impacts of CVE-2026-26115?
The potential impact of CVE-2026-26115 includes unauthorized access and escalation of privileges within the SQL Server environment.