CVE-2026-62836

high
Published 2026-08-07 · Modified 2026-08-07
CVSS v3
8.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
CVSS v4 NEW
not yet in upstream
VIR risk
8.7

Description

Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.

Predictions

Exploit likelihood
91%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Microsoft Security Response Center · View original ↗ · proprietary-no-redistribution
Full prose not cached — VIR stores only structured fields (affected/fixed versions, references) for this source. Click "View original" above for the vendor's full advisory.

Affected

VendorProductVersion
microsoftMicrosoft Teams
microsoftAzure Active Directory
microsoftMicrosoft Power Apps
microsoftMicrosoft SharePoint Online
microsoftAzure Logic Apps
microsoftMicrosoft Purview eDiscovery
microsoftAzure SRE Agent
microsoftMicrosoft Planetary Computer Pro (GeoCatalog)
microsoftApplication Insights Profiler
microsoftMicrosoft Entra Provisioning Service
microsoftAzure SQL Managed Instance
microsoftAzure Service Bus
microsoftAzure SQL Database
microsoftMicrosoft 365 Admin Center
microsoftAzure Confidential Ledger

OS impact

windows Windows Affected 1 release
VersionStatusFixed in
Affected

References

CWEs

CWE-923

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.