Junglewise Threat Intelligence

CVE-2026-20803: Microsoft SQL Server privilege escalation via missing authentication

CVE-2026-20803 · Severity: high · CVSS 7.2 · Published 2026-01-13

Executive brief

Microsoft SQL Server, a widely used database management system, contains a security flaw that could allow an authorized user to gain higher-level permissions than they should have. By exploiting this vulnerability, an attacker who already has high-level access to the database could perform unauthorized administrative actions or access sensitive data. This could lead to a significant breach of data confidentiality and integrity within the corporate environment.

Technical details

A privilege escalation vulnerability exists in Microsoft SQL Server 2022 and 2025 due to missing authentication for a critical function (CWE-306). An attacker with high-privileged credentials (PR:H) can exploit this flaw over the network without user interaction to gain further elevated permissions. The vulnerability affects specific versions of SQL Server 2022 (GDR and CU 22) and SQL Server 2025. Successful exploitation grants the attacker full control over the database's confidentiality, integrity, and availability. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft SQL Server 2022 16.0.0 up to 16.0.1165.1 (GDR); 16.0.0.0 up to 16.0.4230.2 (CU 22)
  • Microsoft SQL Server 2025 17.0.1050.2

Timeline

  • 2026-01-13: disclosed: Initial publication by Microsoft
  • 2026-01-13: advisory: NVD entry created

References

Related threats