CVE-2026-47295: Microsoft SQL Server Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Other sources
Microsoft SQL Server Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47295?
CVE-2026-47295 has a severity rating of 8.8, categorized as high.
How does CVE-2026-47295 affect Microsoft SQL Server?
CVE-2026-47295 allows an authorized attacker to elevate privileges through SQL injection vulnerabilities in Microsoft SQL Server.
Which versions of Microsoft SQL Server are affected by CVE-2026-47295?
CVE-2026-47295 affects Microsoft SQL Server 2016, 2017, 2019, 2022, and 2025, specifically certain cumulative updates.
What is the risk associated with CVE-2026-47295?
CVE-2026-47295 presents a risk rating of 79, indicating a significant potential for exploitation.
How can I mitigate the risks of CVE-2026-47295?
Mitigation steps for CVE-2026-47295 involve applying the latest security patches and updates provided by Microsoft for the affected SQL Server versions.