CVE-2026-20803: Microsoft SQL Server 2022

High severity, CVSS 7.2. EPSS: 1.2% chance of exploitation in the next 30 days.

Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.

Affected products

  • Microsoft SQL Server 2022: from 16.0.1000.6, before 16.0.1165.1 (fixed in 16.0.1165.1); from 16.0.4003.1, before 16.0.4230.2 (fixed in 16.0.4230.2)
  • Microsoft SQL Server 2025: version 17.0.1000.7 only

Published 2026-01-13. Last modified 2026-07-30.