Executive brief
Azure SQL Database is Microsoft's managed relational database service used by organizations to store and manage business-critical data in the cloud. An authenticated attacker with sufficient database permissions can exploit an incorrect permission assignment in a critical resource to escalate their privileges within the database, potentially gaining unauthorized access to sensitive data or administrative functions.
Technical details
This vulnerability stems from incorrect permission assignment for a critical resource within Azure SQL Database. The flaw allows an authorized attacker (one with existing database access) to perform privilege escalation locally within the affected database instance. The attack requires prior authentication and does not require network traversal beyond the database itself. Exploitation enables an attacker to exceed their intended authorization level and access or modify resources they should not be able to reach. Microsoft has released security updates to correct the permission assignment logic.
Affected products
- Microsoft Azure SQL Database
Timeline
- 2026-08-11: disclosed