Junglewise Threat Intelligence

CVE-2026-85878: Microsoft Azure Database for PostgreSQL improper authorization privilege escalation

CVE-2026-85878 · Severity: critical · CVSS 9.9 · Published 2026-09-18

Vendors: Microsoft.

Executive brief

Azure Database for PostgreSQL is a managed database service that enterprises use to store and manage their data in the cloud. An authorized user can exploit improper authorization controls to escalate their privileges and gain elevated access to the database over a network connection, potentially allowing them to access or modify data beyond their intended permissions.

Technical details

An improper authorization vulnerability in Azure Database for PostgreSQL allows an authenticated attacker to escalate privileges over the network. The vulnerability exists in the service's access control logic, enabling an authorized user to gain elevated permissions. This is a network-reachable privilege escalation that requires the attacker to already have valid database credentials.

Affected products

  • Microsoft Azure Database for PostgreSQL

Timeline

  • 2026-09-18: disclosed

References