CVE-2026-55002: Microsoft SQL Server Elevation of Privilege Vulnerability
External control of file name or path in SQL Server allows an authorized attacker to elevate privileges locally.
Other sources
External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.
— Microsoft
Microsoft SQL Server Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55002?
CVE-2026-55002 has a severity rating of 7.8, which is classified as high.
How can I fix CVE-2026-55002?
To address CVE-2026-55002, you should apply the latest security updates for Microsoft SQL Server.
What systems are affected by CVE-2026-55002?
CVE-2026-55002 affects Microsoft SQL Server 2017, 2019, 2022, and 2025 across various update versions.
What type of vulnerability is CVE-2026-55002?
CVE-2026-55002 is categorized as an elevation of privilege vulnerability.
Who can exploit CVE-2026-55002?
An authorized attacker can exploit CVE-2026-55002 to elevate privileges locally in affected SQL Server installations.