CVE-2026-77487: SQL Server Elevation of Privilege Vulnerability
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Other sources
SQL Server Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1200.5Patch KB5122771 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4490.9Patch KB5122772 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1135.8Patch KB5122770 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2190.7Patch KB5122773 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4275.2Patch KB5122768 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2130.4Patch KB5122775 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3550.4Patch KB5122774 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4085.5Patch KB5122769
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must already be authorized to access the affected SQL Server instance. Exploitation can be performed over the network and does not require user interaction.
What is the potential impact?
A successful attacker can elevate privileges on the SQL Server instance. The supplied severity vector indicates potential high impact to confidentiality, integrity, and availability.
Which SQL Server releases are listed as affected?
The affected software list includes SQL Server 2017, SQL Server 2019, SQL Server 2022, and SQL Server 2025, including the listed CU 31, CU 32, CU 26, and CU8 entries respectively.