PT-2026-58246 · Microsoft · Sql Server

CVE-2026-55002

·

Published

2026-07-14

·

Updated

2026-08-04

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SQL Server versions 2016 through 2025
Description An authorized attacker can elevate privileges locally due to external control of a file name or path. This allows an authenticated local user to gain administrative control over the database.
Recommendations Apply the security patch for SQL Server versions 2016 through 2025.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55002

Affected Products

Sql Server