Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-68789: Azure SQL Database lets authorized user gain higher rights

CVE-2026-68789 · published 14 days ago
Summary

A flaw in Azure SQL Database could let someone who already has access run specially crafted queries to boost their permissions. This could allow them to view or change data they shouldn’t. Apply the latest security update from Microsoft as soon as possible and review user permissions.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
microsoft azure sql database -
Original advisory text
Azure SQL Database Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
Severity
9.9 Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published20 Aug 2026
Updated3 Sep 2026
First seen20 Aug 2026
Sources
CVE-2026-68789 · MITRE
Monitor software like this
Free during beta