CVE-2026-77480HighCVSS 8.8

SQL Server Elevation of Privilege Vulnerability

Published
September 11, 2026
Last Modified

🔗 CVE IDs covered (1)

📋 Description

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

🎯 Affected products8

  • Microsoft SQL Server 2017 for x64-based Systems (CU 31)
  • Microsoft SQL Server 2017 for x64-based Systems (GDR)
  • Microsoft SQL Server 2019 for x64-based Systems (CU 32)
  • Microsoft SQL Server 2019 for x64-based Systems (GDR)
  • Microsoft SQL Server 2022 for x64-based Systems (CU 26)
  • Microsoft SQL Server 2022 for x64-based Systems (GDR)
  • Microsoft SQL Server 2025 for x64-based Systems (CU8)
  • Microsoft SQL Server 2025 for x64-based Systems (GDR)

✅ Remediation

KB5122775 (Security Update) — fixed build 14.0.2130.4 KB5122773 (Security Update) — fixed build 15.0.2190.7 KB5122774 (Security Update) — fixed build 14.0.3550.4 KB5122771 (Security Update) — fixed build 16.0.1200.5 KB5122770 (Security Update) — fixed build 17.0.1135.8 KB5122772 (Security Update) — fixed build 15.0.4490.9 KB5122768 (Security Update) — fixed build 16.0.4275.2 KB5122769 (Security Update) — fixed build 17.0.4085.5

🔗 References (17)