
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20803 is a missing authentication for critical function vulnerability in Microsoft SQL Server that allows an authorized, high-privileged attacker to elevate privileges over a network. It affects Microsoft SQL Server 2022 (versions 16.0.4003.1 through 16.0.4230.2 and 16.0.1000.6 through 16.0.1165.1) and SQL Server 2025 (version 17.0.1000.7). The vulnerability was published on January 13, 2026, coinciding with Microsoft's January 2026 Patch Tuesday release. It carries a CVSS v3.1 base score of 7.2 (High), assigned by Microsoft (Microsoft MSRC).
The root cause is classified as CWE-306 (Missing Authentication for Critical Function), meaning a critical SQL Server function can be invoked without proper authentication checks, even when the attacker already holds a high-privileged account. The attack vector is network-based, requires no user interaction, and has low attack complexity, though it does require the attacker to already possess high privileges on the target system. The scope is unchanged, indicating the vulnerability does not allow escape from the SQL Server security context itself. A proof-of-concept reference has been noted at a public blog (cryptobivash.code.blog), though detailed technical write-ups remain limited (Microsoft MSRC).
Successful exploitation allows an authorized attacker to escalate privileges within SQL Server over the network, resulting in high impacts to confidentiality, integrity, and availability of the database system. An attacker who achieves privilege escalation could gain full control over database contents, modify or destroy data, and disrupt database availability. Given SQL Server's typical role as a backend for critical business applications, compromise could expose sensitive organizational data and enable lateral movement within the environment (Microsoft MSRC, Feedly).
Microsoft released patches on January 13, 2026, as part of the January 2026 Patch Tuesday update. Administrators should upgrade SQL Server 2022 to version 16.0.4230.2 (CU 22) or 16.0.1165.1 (GDR), and SQL Server 2025 to version 17.0.1050.2 (GDR) or later. As interim mitigations, restrict network access to SQL Server instances using firewalls and network segmentation, limit high-privileged SQL Server accounts to only those users who require them, and monitor database activity for suspicious privilege escalation attempts. Amazon RDS Custom users should apply the latest GDR updates as noted in AWS's update announcement (Microsoft MSRC, SQL Server 2022 Blog, SQL Server 2025 Blog).
The vulnerability was covered as part of broader January 2026 Patch Tuesday reporting by multiple security outlets including Cybersecurity News, GBHackers, Sophos, and Zero Day Initiative, which noted it among the 113–114 CVEs addressed that month (Sophos Blog, ZDI Blog). Flare.io published post-Patch Tuesday threat intelligence tracking cybercrime activity following the release (Flare.io Blog). Community discussion was moderate, with SQL Server-focused blogs such as SQLFingers and CuratedSQL highlighting the update for database administrators (SQLFingers).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."