← Back to overview

CVE-2026-68789 describes an SQL injection vulnerability in Microsoft Azure SQL Database. The flaw involves improper neutralization of special elements in SQL commands, allowing an authorized attacker to elevate privileges over a network. The vulnerability is classified as a privilege escalation issue exploitable remotely. It requires the attacker to already have some level of authorization before exploitation. Microsoft has published an advisory via the Microsoft Security Response Center (MSRC). The vulnerability is tracked in the National Vulnerability Database (NVD) at NIST. Given the cloud database context, the potential impact on sensitive data and infrastructure is significant.

Affected products

  • Microsoft Azure SQL Database

Related CVE's

  • CVE-2026-68789

Categories

  • Cloud & Virtualization
  • Database & Storage
  • Identity & Access