PT-2026-24260 · Microsoft · Sql Server 2016 Sp3+1

Erland Sommarskog

·

Published

2026-03-10

·

Updated

2026-03-11

·

CVE-2026-21262

CVSS v3.1
8.8
VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SQL Server versions 2016 SP3 through 2025
Description An improper access control issue in SQL Server allows an authorized attacker to elevate privileges over a network. An attacker can gain
sysadmin
privileges remotely on affected SQL Server instances.
Recommendations Apply the patch released in Microsoft’s March 2026 Patch Tuesday to all SQL Server versions from 2016 SP3 through 2025.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-21262

Affected Products

Sql Server 2016 Sp3
Sql Server 2025