CVE-2026-77483: SQL Server Elevation of Privilege Vulnerability
SQL Server Elevation of Privilege Vulnerability
Other sources
Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4085.5Patch KB5122769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1135.8Patch KB5122770 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2130.4Patch KB5122775 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3550.4Patch KB5122774 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1200.5Patch KB5122771 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2190.7Patch KB5122773 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4275.2Patch KB5122768 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4490.9Patch KB5122772
Event History
Frequently Asked Questions
Which SQL Server deployments should be prioritized for review?
Review Microsoft SQL Server 2017, 2019, 2022, and 2025 deployments, including the listed SQL Server 2017 CU 31, SQL Server 2019 CU 32, and SQL Server 2022 CU 26 releases.
What level of access does an attacker need?
The attacker must already be authorized to access SQL Server and must be able to reach it over the network. No user interaction is required.
What could successful exploitation allow?
Successful exploitation can elevate the authorized attacker’s privileges. The supplied severity data indicates high potential impact to confidentiality, integrity, and availability.