SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-47295

HIGH · CVSS 8.8 EPSS 0.92%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

An SQL injection vulnerability in SQL Server allows authorized attackers to manipulate SQL commands, potentially leading to privilege escalation over the network. Organizations using SQL Server should prioritize patching this vulnerability to mitigate the risk of unauthorized access and data compromise. Immediate action is recommended for those with sensitive data or critical infrastructure relying on SQL Server.

CVE
CVE-2026-47295
Severity
HIGH
CVSS
8.8
EPSS
0.92%

Original NVD Description

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Related CVEs

Other vulnerabilities affecting the same vendor(s)