SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-47296

HIGH · CVSS 7.5 EPSS 0.50%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

SQL Server is vulnerable to an SQL injection attack due to improper neutralization of special elements in SQL commands, allowing an authorized attacker to escalate privileges remotely. This vulnerability poses a significant risk as it can lead to unauthorized access and manipulation of sensitive data. Organizations using SQL Server should prioritize this issue to mitigate potential exploitation and safeguard their data integrity.

CVE
CVE-2026-47296
Severity
HIGH
CVSS
7.5
EPSS
0.50%

Original NVD Description

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Related CVEs

Other vulnerabilities affecting the same vendor(s)