Server-Side Request Forgery Vulnerability in Azure SQL Database by Microsoft
CVE-2026-69502

10CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
21 August 2026

What is CVE-2026-69502?

A security flaw in Azure SQL Database allows unauthorized attackers to exploit server-side request forgery (SSRF) vulnerabilities. This can enable them to gain elevated privileges and manipulate network requests, potentially leading to unauthorized access to sensitive data or services. Users of Azure SQL Database should ensure they apply the necessary patches to safeguard their systems from these serious threats.

Affected Version(s)

Azure SQL Database -

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.