AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-66309

CRITICAL · CVSS 9.1 EPSS 0.48%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-08-24

CyberRota Analysis

AI-Generated

An improper access control vulnerability in Azure SQL Database enables an authorized attacker to elevate their privileges remotely, potentially compromising sensitive data and system integrity. Organizations utilizing Azure SQL Database should prioritize patching this critical vulnerability to mitigate the risk of unauthorized access and data breaches. Immediate action is recommended for all users of the affected service to safeguard their environments.

CVE
CVE-2026-66309
Severity
CRITICAL
CVSS
9.1
EPSS
0.48%

Original NVD Description

Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

Related CVEs

Other vulnerabilities affecting the same vendor(s)