CVE-2026-65669: Microsoft SQL Server Elevation of Privilege Vulnerability
Published Sep 8, 2026
·Updated
Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.
Other sources
Microsoft SQL Server Elevation of Privilege Vulnerability
— Microsoft
Affected Software
1 affected componentFixes available
Microsoft SQL Server Management Studio 22<22.8.2
22.8.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 22.8.2
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:13 PM
Data Sourced
via MITRE·05:13 PM
DescriptionSeverity
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need in order to exploit this issue?
The vector is network-based and no privileges are required. Exploitation requires user interaction.
2
Which software is identified as affected in the available data?
The affected software listed is Microsoft SQL Server Management Studio 22 from Microsoft. No affected version range or configuration details are provided.