
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21262 is a privilege escalation vulnerability in Microsoft SQL Server caused by improper access control (CWE-284), allowing an authenticated attacker with low-level privileges to elevate to full sysadmin control over the network without user interaction. Disclosed and patched on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday, it affects SQL Server 2016, 2017, 2019, 2022, and 2025 across multiple cumulative update and GDR branches. It carries a CVSS v3.1 base score of 8.8 (High) (Microsoft MSRC, Feedly).
The root cause is improper access control (CWE-284) within the SQL Server engine, which fails to adequately enforce privilege boundaries for authenticated network users. An attacker with a low-privileged SQL Server account can exploit this flaw over the network (attack vector: Network, attack complexity: Low, privileges required: Low, user interaction: None) to escalate to sysadmin-level privileges. Feedly's CWE estimate also flags a potential use-after-free (CWE-416) component, though Microsoft's official classification is CWE-284. No public proof-of-concept exploit code has been confirmed, but exploitation has been reported in the wild (Microsoft MSRC, Tenable Blog, undercodetesting.com).
Successful exploitation grants an attacker complete sysadmin control over the affected SQL Server instance, enabling full read, write, and deletion of all hosted databases. This can result in mass data exfiltration, destruction of critical business data, and potential lateral movement within the broader network infrastructure by leveraging the SQL Server's trusted position and linked server configurations. All SQL Server versions from 2016 through 2025 are in scope, making the blast radius significant for enterprise environments (Microsoft MSRC, Feedly).
EXEC xp_cmdshell to run OS-level commands, exfiltrate data, create backdoor accounts, or pivot to other systems via linked servers (Microsoft MSRC, undercodetesting.com).sp_addsrvrolemember, xp_cmdshell, RECONFIGURE); Windows Event Logs showing new SQL Server logins followed by privilege changes.sqlservr.exe (e.g., cmd.exe, powershell.exe, net.exe); execution of xp_cmdshell by accounts not previously authorized to use it.Microsoft released patches on March 10, 2026 as part of Patch Tuesday. Administrators should apply the following fixed versions immediately:
As a temporary mitigation, restrict network access to SQL Server instances to trusted hosts only, enforce the principle of least privilege for all SQL logins, and monitor for anomalous privilege escalation activity. Amazon RDS has also released updated support for the patched CU/GDR versions (Microsoft MSRC, AWS).
The vulnerability received broad coverage across the security community as part of the March 2026 Patch Tuesday cycle, with researchers from Tenable, Rapid7, Qualys, Sophos, Cisco Talos, and Zero Day Initiative all publishing analyses (Tenable Blog, Rapid7, ZDI). KrebsOnSecurity and BleepingComputer highlighted it as one of the most critical issues in the March update, and Computer Weekly specifically noted it as a zero-day in SQL Server (KrebsOnSecurity, Computer Weekly). Reddit communities (r/SQL, r/SQLServer, r/SecOpsDaily) actively discussed the vulnerability and its implications for database administrators. Recorded Future's March 2026 CVE landscape report identified it as one of 31 high-impact vulnerabilities for the month (Recorded Future).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."