CVE-2026-66309 describes an improper access control vulnerability in Microsoft Azure SQL Database. The flaw allows an authorized attacker to elevate their privileges over a network. The vulnerability was published by the National Vulnerability Database (NVD) and has a corresponding Microsoft Security Response Center (MSRC) advisory. The attack vector is network-based, meaning exploitation can occur remotely. The attacker must already be authorized, indicating this is a post-authentication privilege escalation issue. Microsoft has issued guidance through its update guide. The vulnerability is classified as high criticality. No additional technical details or proof-of-concept exploits are referenced in the article.