CVE-2026-47296: Microsoft SQL Server Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Other sources
Microsoft SQL Server Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4480.2Patch KB5102335 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.0.7095.1Patch KB5102339 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.0.6500.1Patch KB5102340 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2180.2Patch KB5102336 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2120.1Patch KB5102338 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4060.2Patch KB5101346 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4262.2Patch KB5101347 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3540.1Patch KB5102337 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1190.2Patch KB5102334 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1125.2Patch KB5102333
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47296?
CVE-2026-47296 has a severity score of 7.8, classified as high.
How does CVE-2026-47296 affect Microsoft SQL Server?
CVE-2026-47296 allows an authorized attacker to elevate privileges through SQL injection in Microsoft SQL Server.
Which versions of Microsoft SQL Server are affected by CVE-2026-47296?
CVE-2026-47296 affects Microsoft SQL Server 2016, 2017, 2019, 2022, and corresponding feature packs.
What is the nature of the vulnerability in CVE-2026-47296?
CVE-2026-47296 involves improper neutralization of special elements in SQL commands, leading to potential privilege escalation.
How can organizations mitigate CVE-2026-47296?
Organizations are advised to apply patches and updates provided by Microsoft to mitigate CVE-2026-47296.