PT-2026-2656 · Microsoft · Sql Server

Published

2026-01-13

·

Updated

2026-01-17

·

CVE-2026-20803

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft SQL Server (affected versions not specified)
Description A missing authentication check for a critical function in Microsoft SQL Server can allow an authorized attacker to elevate privileges over a network. The issue, caused by missing authentication, enables a high-privileged SQL Server user to gain debugging privileges and potentially dump system memory, which could expose sensitive information like secrets and credentials.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2026-00478
CVE-2026-20803

Affected Products

Sql Server