Elevation of Privilege Vulnerability in Microsoft SQL Server
CVE-2026-20803
7.2HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 13 January 2026
What is CVE-2026-20803?
An authentication flaw in Microsoft SQL Server exposes a critical function that can be exploited by attackers with authorized access to escalate their privileges across the network. This vulnerability allows them to perform unauthorized actions and gain broader control over the system, potentially leading to data breaches and integrity issues.
Affected Version(s)
Microsoft SQL Server 2022 (GDR) x64-based Systems 16.0.0 < 16.0.1165.1
Microsoft SQL Server 2022 for x64-based Systems (CU 22) 16.0.0.0 < 16.0.4230.2
Microsoft SQL Server 2025 for x64-based Systems (GDR) 17.0.1050.2