Junglewise Threat Intelligence

CVE-2026-55002: Microsoft SQL Server privilege escalation via external path control

CVE-2026-55002 · Severity: high · CVSS 7.8 · Published 2026-07-14

Executive brief

A security vulnerability has been identified in Microsoft SQL Server, a widely used database management system. An attacker who already has basic access to the local system could exploit this flaw to gain higher-level administrative privileges. This could allow them to access sensitive data, modify system configurations, or disrupt database operations.

Technical details

This vulnerability is classified as an External Control of File Name or Path (CWE-73) within Microsoft SQL Server. The flaw allows a locally authenticated attacker with low privileges to manipulate file paths used by the SQL Server process. By providing specially crafted input to a vulnerable component, the attacker can achieve local privilege escalation (LPE), potentially gaining full administrative control over the database instance. The vulnerability affects multiple versions of SQL Server ranging from 2016 to 2025. Microsoft has released security updates to address this issue across the affected versions.

Affected products

  • Microsoft SQL Server 2016 Service Pack 3 (GDR) 13.0.0 to 13.0.6500.1
  • Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack 13.0.0 to 13.0.7095.1
  • Microsoft SQL Server 2017 (CU 31) 14.0.0 to 14.0.3540.1
  • Microsoft SQL Server 2017 (GDR) 14.0.0 to 14.0.2120.1
  • Microsoft SQL Server 2019 (CU 32) 15.0.0.0 to 15.0.4480.2
  • Microsoft SQL Server 2019 (GDR) 15.0.0 to 15.0.2180.2
  • Microsoft SQL Server 2022 (GDR) 16.0.0 to 16.0.1190.2
  • Microsoft SQL Server 2022 (CU 25) 16.0.4260.1 to 16.0.4262.2
  • Microsoft SQL Server 2025 (CU 6) 17.0.4060.2
  • Microsoft SQL Server 2025 (GDR) 17.0.1050.2 to 17.0.1125.2

Timeline

  • 2026-07-14: advisory: Initial publication by Microsoft and NVD

References

Related threats