Executive brief
Azure Database for PostgreSQL is a managed database service that enterprises use to store and manage their data in the cloud. An authorized user can exploit improper authorization controls to escalate their privileges and gain elevated access to the database over a network connection, potentially allowing them to access or modify data beyond their intended permissions.
Technical details
An improper authorization vulnerability in Azure Database for PostgreSQL allows an authenticated attacker to escalate privileges over the network. The vulnerability exists in the service's access control logic, enabling an authorized user to gain elevated permissions. This is a network-reachable privilege escalation that requires the attacker to already have valid database credentials.
Affected products
- Microsoft Azure Database for PostgreSQL
Timeline
- 2026-09-18: disclosed