
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26115 is a privilege escalation vulnerability in Microsoft SQL Server caused by improper validation of a specified type of input (CWE-1287). It allows an authorized, low-privileged attacker to elevate privileges over a network without requiring user interaction. Affected versions span SQL Server 2016, 2017, 2019, 2022, and 2025 across multiple cumulative update and GDR branches. The vulnerability was disclosed and patched on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday. It carries a CVSS v3.1 base score of 8.8 (High) (Microsoft MSRC, Feedly).
The root cause is classified as CWE-1287 (Improper Validation of Specified Type of Input), where SQL Server fails to adequately validate the type of input supplied by an authenticated user, enabling privilege escalation. The attack vector is network-based, requires low privileges (a valid database account), low attack complexity, and no user interaction, making it straightforward to exploit for any authenticated user with network access to the SQL Server instance. No public technical write-up or proof-of-concept code detailing the specific vulnerable component or payload has been published as of the time of this report (Microsoft MSRC, Tenable).
Successful exploitation allows a low-privileged authenticated attacker to escalate to administrative-level access on the SQL Server instance, resulting in high confidentiality, integrity, and availability impacts. An attacker could read, modify, or delete all database contents, execute operating system commands via SQL Server features (e.g., xp_cmdshell if enabled), and potentially disrupt database availability. All affected SQL Server versions (2016 through 2025) are at risk, and compromise of a database server could facilitate lateral movement within an organization's network (Microsoft MSRC, Feedly).
Microsoft released patches on March 10, 2026. Organizations should update to the following fixed versions: SQL Server 2016 SP3 GDR ≥ 13.0.6480.4 or SP3 Azure Connect FP ≥ 13.0.7075.5; SQL Server 2017 GDR ≥ 14.0.2100.4 or CU31 ≥ 14.0.3520.4; SQL Server 2019 GDR ≥ 15.0.2160.4 or CU32 ≥ 15.0.4460.4; SQL Server 2022 GDR ≥ 16.0.1170.5 or CU23 ≥ 16.0.4240.4; SQL Server 2025 GDR ≥ 17.0.1050.2 or CU2 ≥ 17.0.4020.2. As interim mitigations, restrict network access to SQL Server instances to trusted hosts only, apply the principle of least privilege to database accounts, and monitor SQL Server audit logs for suspicious privilege escalation activity. Amazon RDS has also released updated CU/GDR builds incorporating these fixes (Microsoft MSRC, AWS).
The vulnerability was covered as part of broader March 2026 Patch Tuesday roundups by multiple security vendors and researchers. Tenable, Rapid7, Sophos, Cisco Talos, and Zero Day Initiative all included CVE-2026-26115 in their Patch Tuesday analyses, noting it as a notable SQL Server privilege escalation issue among the 83 CVEs addressed that month (Tenable, Rapid7, Sophos, ZDI). Community sentiment reflected standard urgency for patching SQL Server instances, with no extraordinary alarm given the absence of public exploits or active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."