Junglewise Threat Intelligence

CVE-2026-77487: Microsoft SQL Server privilege escalation over network

CVE-2026-77487 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

SQL Server is Microsoft's relational database platform used by enterprises to store and manage critical business data. An improper access control flaw allows an authorized database user to escalate their privileges on a remote server, potentially granting them administrator-level access and the ability to read, modify, or delete sensitive data across the entire database.

Technical details

The vulnerability is a privilege escalation flaw rooted in improper access control enforcement within SQL Server. An attacker with valid database credentials can exploit this flaw over the network to elevate their privileges without requiring additional authentication. The attack is network-based, meaning it can be executed remotely by an authorized user. Successful exploitation grants the attacker elevated database privileges, potentially leading to unauthorized data access, modification, or deletion. A patch is available from Microsoft Security Response Center.

Affected products

  • Microsoft SQL Server

Timeline

  • 2026-09-08: disclosed

References

Related threats