CVE-2026-62836Critical
Azure SQL Managed Instance Elevation of Privilege Vulnerability
Assessment
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
- Severity
- Critical
- CVSS base score
- 8.7CVSS:3.1/
AV:N/ AC:H/ PR:N/ UI:N/ S:C/ C:H/ I:H/ A:N/ E:U/ RL:O/ RC:C - Impact
- Elevation of Privilege
- EPSS, next 30 days
- 0.6%Higher than 49% of scored CVEs · FIRST model run 26 Sep 2026 · about EPSS
- Exploitability
- Not assessed
- Publicly disclosed
- No
- Customer action
- Not required (service-side fix)
- Component
- Azure SQL Managed Instance
- Weakness
- CWE-923: Improper Restriction of Communication Channel to Intended Endpoints
- Issued by
- Microsoft
- Published
- 6 Aug 2026 · August 2026
- Last revised
- 6 Aug 2026
Updates that fix it
0 KBsNo KB listed
MSRC lists no downloadable update, which usually means a service-side fix or a release-notes update. Check the MSRC advisory.
Affected products
Microsoft Office1 affected product
- Azure SQL Managed Instance