CVE-2026-26115 is a high-severity privilege escalation vulnerability (CVSS 8.8) affecting Microsoft SQL Server versions 2016, 2017, 2019, 2022, and 2025. This flaw, caused by improper input validation, allows an authorized attacker to elevate privileges over a network with low attack complexity. Successful exploitation leads to high impacts on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, nor is public exploit code available in common repositories like Metasploit or ExploitDB. The vulnerability has garnered some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.0.6300.2, < 13.0.6480.4CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2016:*:*:*:*:*:*:x64:* | ||
>= 13.0.7000.253, < 13.0.7075.5CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2016:*:*:*:*:*:*:x64:* | ||
>= 14.0.1000.169, < 14.0.2100.4CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:* | ||
>= 14.0.3006.16, < 14.0.3520.4CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:* | ||
>= 15.0.2000.5, < 15.0.2160.4CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.