CVE-2026-69502: Azure SQL Database Elevation of Privilege Vulnerability
Published Aug 20, 2026
·Updated
Azure SQL Database Elevation of Privilege Vulnerability
Other sources
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
2 affected components
Microsoft Azure SQL Database
Microsoft Azure SQL Database
Event History
Aug 20, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
Aug 21, 2026
CVE Published
via MITRE·04:03 PM
Data Sourced
via MITRE·04:03 PM
DescriptionSeverity
Data Sourced
via NVD·04:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who can exploit this vulnerability?
The available information describes exploitation by an unauthorized attacker over a network. It does not indicate that prior authentication or user interaction is required.
2
What is the security impact?
Successful exploitation can allow elevation of privilege in Azure SQL Database. The supplied severity vector indicates high confidentiality and integrity impact, with no availability impact stated.
3
Is a specific Azure SQL Database version or configuration known to be affected?
No affected versions, deployment configurations, or mitigation details are provided in the available data.