Junglewise Threat Intelligence

CVE-2026-63522: Microsoft Azure SQL Database privilege escalation via incorrect permission assignment

CVE-2026-63522 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Azure Sql Database. Vendors: Microsoft.

Executive brief

Azure SQL Database is Microsoft's managed relational database service used by organizations to store and manage business-critical data in the cloud. An authenticated attacker with sufficient database permissions can exploit an incorrect permission assignment in a critical resource to escalate their privileges within the database, potentially gaining unauthorized access to sensitive data or administrative functions.

Technical details

This vulnerability stems from incorrect permission assignment for a critical resource within Azure SQL Database. The flaw allows an authorized attacker (one with existing database access) to perform privilege escalation locally within the affected database instance. The attack requires prior authentication and does not require network traversal beyond the database itself. Exploitation enables an attacker to exceed their intended authorization level and access or modify resources they should not be able to reach. Microsoft has released security updates to correct the permission assignment logic.

Affected products

  • Microsoft Azure SQL Database

Timeline

  • 2026-08-11: disclosed

References

Related threats