Junglewise Threat Intelligence

CVE-2026-73028: Microsoft SQL Server privilege escalation via improper access control

CVE-2026-73028 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

SQL Server is a widely-used database platform that stores critical business data and handles application queries. This vulnerability allows an attacker with basic database access to gain elevated privileges and potentially access sensitive data, modify records, or disrupt database operations across a network.

Technical details

The vulnerability stems from improper access control in SQL Server that permits an authorized attacker to escalate privileges over a network connection. The flaw allows an attacker who already has some level of database access to gain elevated privileges without proper authorization checks. Attack requires network connectivity to SQL Server and prior database authentication; however, no additional user interaction is needed once access is obtained. Successful exploitation could allow an attacker to perform administrative actions, access restricted data, or modify database schemas.

Affected products

  • Microsoft SQL Server

Timeline

  • 2026-09-08: disclosed

References

Related threats