CVE-2026-20803
Microsoft Microsoft SQL Server 2022 (GDR), Microsoft SQL Server 2022 for x64-based Systems (CU 22), Microsoft SQL Server 2025 for x64-based Systems (GDR)
Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.
- CVSS
- 7.2
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.01.14