← Terug naar overzicht

CVE-2026-66309 describes an improper access control vulnerability in Microsoft Azure SQL Database. The flaw allows an authorized attacker to elevate their privileges over a network. The vulnerability was published by the National Vulnerability Database (NVD) and has a corresponding Microsoft Security Response Center (MSRC) advisory. The attack vector is network-based, meaning exploitation can occur remotely. The attacker must already be authorized, indicating this is a post-authentication privilege escalation issue. Microsoft has issued guidance through its update guide. The vulnerability is classified as high criticality. No additional technical details or proof-of-concept exploits are referenced in the article.

Affected products

  • Azure SQL Database

Related CVE's

  • CVE-2026-66309

Categories

  • Cloud & Virtualization
  • Database & Storage
  • Identity & Access