CVE-2026-85878: Azure Database for PostgreSQL Elevation of Privilege Vulnerability
Published Sep 17, 2026
·Updated
Azure Database for PostgreSQL Elevation of Privilege Vulnerability
Other sources
Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
1 affected component
Microsoft Azure HorizonDB
Event History
Sep 17, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·11:04 PM
Data Sourced
via MITRE·11:04 PM
DescriptionSeverity
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must already be authorized to access the affected Azure Database for PostgreSQL service. Exploitation can be performed over the network and does not require user interaction.
2
What is the potential impact if exploitation succeeds?
A successful attacker can elevate privileges. The supplied severity vector indicates potential high impact to confidentiality, integrity, and availability, with impact extending beyond the initially authorized security scope.