CVE-2026-62836CWE-923

CVE-2026-62836

High · published August 7, 2026

CVSS v3.1
8.7
EPSS
0%
Percentile
36.5
In the wild
Unconfirmed
What it is

Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.

The record
Technical detail
CVSS v3.1
8.7 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00435 · 36.5th percentile
Weakness
CWE-923 · Improper Restriction of Communication Channel to Intended Endpoints
Published
2026-08-07T04:16Z
Affected products (1)
ProductVersionsFixed in
microsoft/azure_sql_managed_instanceall versions
References (1)
EPSS history
Timeline
  • 06 AUG 22:37Z
    Azure SQL Managed Instance Elevation of Privilege Vulnerability
    cvelistv5