CVE-2026-68782: Azure SQL Database Elevation of Privilege Vulnerability
Azure SQL Database Elevation of Privilege Vulnerability
Other sources
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must already be authorized to access Azure SQL Database and be able to reach the affected service over the network. No user interaction is required.
What level of impact could successful exploitation have?
Successful SQL injection can allow the authorized attacker to elevate privileges. The supplied severity vector indicates potential high impact to confidentiality, integrity, and availability, including impact beyond the initially affected security scope.
How urgent is remediation?
The issue is rated critical with a 9.9 severity score. The remediation level is listed as official, but the provided data does not identify affected versions or specific update guidance.