PT-2026-2656 · Microsoft · Sql Server

CVE-2026-20803

·

Published

2026-01-13

·

Updated

2026-01-17

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft SQL Server (affected versions not specified)
Description A missing authentication check for a critical function in Microsoft SQL Server can allow an authorized attacker to elevate privileges over a network. The issue, caused by missing authentication, enables a high-privileged SQL Server user to gain debugging privileges and potentially dump system memory, which could expose sensitive information like secrets and credentials.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

LPE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00478
CVE-2026-20803

Affected Products

Sql Server