CVE-2026-26115

Description

Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.104

Associated Vulnerability

VulnerabilityOS Platform
SQL Server Elevation of Privilege Vulnerability for SQL Server 2016 SP3 (KB5077474)Windows
SQL Server Elevation of Privilege Vulnerability for SQL Server 2016 SP3 Azure Connect Feature Pack (KB5077473)Windows
SQL Server Elevation of Privilege Vulnerability for SQL Server 2017 RTM CU (KB5077471)Windows
SQL Server Elevation of Privilege Vulnerability for SQL Server 2017 RTM (KB5077472)Windows
SQL Server Elevation of Privilege Vulnerability for SQL Server 2019 RTM CU (KB5077469)Windows
SQL Server Elevation of Privilege Vulnerability for SQL Server 2019 RTM (KB5077470)Windows
SQL Server Elevation of Privilege Vulnerability for SQL Server 2022 RTM CU (KB5077464)Windows
SQL Server Elevation of Privilege Vulnerability for SQL Server 2022 RTM (KB5077465)Windows
SQL Server Elevation of Privilege Vulnerability for SQL Server 2025 RTM CU (KB5077466)Windows
SQL Server Elevation of Privilege Vulnerability for SQL Server 2025 RTM (KB5077468)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-43692Security Update for SQL Server 2016 SP3 (KB5077474)
PATCH-43691Security Update for SQL Server 2016 SP3 Azure Connect Feature Pack (KB5077473)
PATCH-43694Security Update for SQL Server 2017 RTM CU (KB5077471)
PATCH-43693Security Update for SQL Server 2017 RTM (KB5077472)
PATCH-43696Security Update for SQL Server 2019 RTM CU (KB5077469)
PATCH-43695Security Update for SQL Server 2019 RTM (KB5077470)
PATCH-43698Security Update for SQL Server 2022 RTM CU (KB5077464)
PATCH-43697Security Update for SQL Server 2022 RTM (KB5077465)
PATCH-43700Security Update for SQL Server 2025 RTM CU (KB5077466)
PATCH-43699Security Update for SQL Server 2025 RTM (KB5077468)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234