PT-2026-2656 · Microsoft · Sql Server
Published
2026-01-13
·
Updated
2026-01-17
·
CVE-2026-20803
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft SQL Server (affected versions not specified)
Description
A missing authentication check for a critical function in Microsoft SQL Server can allow an authorized attacker to elevate privileges over a network. The issue, caused by missing authentication, enables a high-privileged SQL Server user to gain debugging privileges and potentially dump system memory, which could expose sensitive information like secrets and credentials.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sql Server