← Back

CVE-2026-20803

nvd nist
Published: Jan 13, 2026Modified: Jun 17, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: secure@microsoft.com (Secondary)

Description

Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.

Affected (3)

2 products
Sql Server 2022
Sql Server 2025
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
From 16.0.1000.6 to 16.0.1165.1
From 16.0.4003.1 to 16.0.4230.2
Version 17.0.1000.7

References (1)

Timeline

No history available yet.