CVE-2026-47296Important
Microsoft SQL Server Elevation of Privilege Vulnerability
Assessment
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
- Severity
- Important
- CVSS base score
- 7.5CVSS:3.1/
AV:N/ AC:H/ PR:L/ UI:N/ S:U/ C:H/ I:H/ A:H - Impact
- Elevation of Privilege
- EPSS, next 30 days
- 0.7%Higher than 50.9% of scored CVEs · FIRST model run 26 Sep 2026 · about EPSS
- Exploitability
- Exploitation Less Likely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- SQL Server
- Weakness
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Issued by
- Microsoft
- Published
- 14 Jul 2026 · July 2026
- Last revised
- 14 Jul 2026
Updates that fix it
10 KBs| KB | Type | Restart | Applies to | Other CVEs |
|---|---|---|---|---|
| KB5101346 | Security Update | — | Microsoft SQL Server 2025 for x64-based Systems (CU6) | All CVEs in KB5101346 |
| KB5101347 | Security Update | — | Microsoft SQL Server 2022 for x64-based Systems (CU 25) | All CVEs in KB5101347 |
| KB5102333 | Security Update | — | Microsoft SQL Server 2025 for x64-based Systems (GDR) | All CVEs in KB5102333 |
| KB5102334 | Security Update | — | Microsoft SQL Server 2022 for x64-based Systems (GDR) | All CVEs in KB5102334 |
| KB5102335 | Security Update | — | Microsoft SQL Server 2019 for x64-based Systems (CU 32) | All CVEs in KB5102335 |
| KB5102336 | Security Update | — | Microsoft SQL Server 2019 for x64-based Systems (GDR) | All CVEs in KB5102336 |
| KB5102337 | Security Update | — | Microsoft SQL Server 2017 for x64-based Systems (CU 31) | All CVEs in KB5102337 |
| KB5102338 | Security Update | — | Microsoft SQL Server 2017 for x64-based Systems (GDR) | All CVEs in KB5102338 |
| KB5102339 | Security Update | — | Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack | All CVEs in KB5102339 |
| KB5102340 | Security Update | — | Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR) | All CVEs in KB5102340 |
Affected products
SQL Server10 affected products
- Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)
- Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack
- Microsoft SQL Server 2017 for x64-based Systems (CU 31)
- Microsoft SQL Server 2017 for x64-based Systems (GDR)
- Microsoft SQL Server 2019 for x64-based Systems (CU 32)
- Microsoft SQL Server 2019 for x64-based Systems (GDR)
- Microsoft SQL Server 2022 for x64-based Systems (CU 25)
- Microsoft SQL Server 2022 for x64-based Systems (GDR)
- Microsoft SQL Server 2025 for x64-based Systems (CU6)
- Microsoft SQL Server 2025 for x64-based Systems (GDR)