CVE-2026-26115HighCVSS 8.8
SQL Server Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.
🎯 Affected products10
- Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)
- Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack
- Microsoft SQL Server 2017 for x64-based Systems (CU 31)
- Microsoft SQL Server 2017 for x64-based Systems (GDR)
- Microsoft SQL Server 2019 for x64-based Systems (CU 32)
- Microsoft SQL Server 2019 for x64-based Systems (GDR)
- Microsoft SQL Server 2022 for x64-based Systems (CU 23)
- Microsoft SQL Server 2022 for x64-based Systems (GDR)
- Microsoft SQL Server 2025 for x64-based Systems (CU2)
- Microsoft SQL Server 2025 for x64-based Systems (GDR)
✅ Remediation
KB5077468 (Security Update) — fixed build 17.0.1105.2 KB5077472 (Security Update) — fixed build 14.0.2100.4 KB5077474 (Security Update) — fixed build 13.0.6480.4 KB5077471 (Security Update) — fixed build 14.0.3520.4 KB5077465 (Security Update) — fixed build 16.0.1170.5 KB5077469 (Security Update) — fixed build 15.0.4460.4 KB5077464 (Security Update) — fixed build 16.0.4240.4 KB5077466 (Security Update) — fixed build 17.0.4020.2 KB5077470 (Security Update) — fixed build 15.0.2160.4 KB5077473 (Monthly Rollup) — fixed build 13.0.7075.5
🔗 References (21)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26115
- patchhttps://www.microsoft.com/download/details.aspx?id=108589
- referencehttps://support.microsoft.com/help/5077468
- patchhttps://www.microsoft.com/download/details.aspx?id=108586
- referencehttps://support.microsoft.com/help/5077472
- patchhttps://www.microsoft.com/download/details.aspx?id=108590
- referencehttps://support.microsoft.com/help/5077474
- patchhttps://www.microsoft.com/download/details.aspx?id=108585
- referencehttps://support.microsoft.com/help/5077471
- patchhttps://www.microsoft.com/download/details.aspx?id=108584
- referencehttps://support.microsoft.com/help/5077465
- patchhttps://www.microsoft.com/download/details.aspx?id=108592
- referencehttps://support.microsoft.com/help/5077469
- patchhttps://www.microsoft.com/download/details.aspx?id=108583
- referencehttps://support.microsoft.com/help/5077464
- patchhttps://www.microsoft.com/download/details.aspx?id=108588
- referencehttps://support.microsoft.com/help/5077466
- patchhttps://www.microsoft.com/download/details.aspx?id=108587
- referencehttps://support.microsoft.com/help/5077470
- patchhttps://www.microsoft.com/download/details.aspx?id=108591
- referencehttps://support.microsoft.com/help/5077473