CVE-2026-56162

critical
Published 2026-08-07 · Modified 2026-08-07
CVSS v3
10.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v4 NEW
not yet in upstream
VIR risk
10.0

Description

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

Predictions

Exploit likelihood
98%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Microsoft Security Response Center · View original ↗ · proprietary-no-redistribution
Full prose not cached — VIR stores only structured fields (affected/fixed versions, references) for this source. Click "View original" above for the vendor's full advisory.

Affected

VendorProductVersion
microsoftMicrosoft Teams
microsoftAzure Active Directory
microsoftMicrosoft Power Apps
microsoftMicrosoft SharePoint Online
microsoftAzure Logic Apps
microsoftMicrosoft Purview eDiscovery
microsoftAzure SRE Agent
microsoftMicrosoft Planetary Computer Pro (GeoCatalog)
microsoftApplication Insights Profiler
microsoftMicrosoft Entra Provisioning Service
microsoftAzure SQL Managed Instance
microsoftAzure Service Bus
microsoftAzure SQL Database
microsoftMicrosoft 365 Admin Center
microsoftAzure Confidential Ledger

OS impact

windows Windows Affected 1 release
VersionStatusFixed in
Affected

References

CWEs

CWE-287

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.