• PATCH AVAILABLE

CVE-2026-62836: pre-auth privilege escalation in Microsoft Azure SQL Managed Instance

An unauthenticated remote attacker can elevate privileges against Azure SQL Managed Instance by abusing improper restriction of communication channels, allowing access escalation over the network. This issue is tracked as CVE-2026-62836. Microsoft identifies the flaw in the Azure SQL Managed Instance branch; vendor guidance does not list specific fixed version numbers. Exploitation requires network access and does not require valid credentials or user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
10CRITICAL
EPSS
0.00648
CWE
CWE-923
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a network-accessible, no-authentication privilege escalation with a CVSS 10.0 rating; prioritize reducing exposure of Azure SQL Managed Instance endpoints and apply Microsoft guidance or patches as soon as they are available.

What is CVE-2026-62836?

An unauthenticated remote attacker can elevate privileges against Azure SQL Managed Instance by abusing improper restriction of communication channels, allowing access escalation over the network. This issue is tracked as CVE-2026-62836. Microsoft identifies the flaw in the Azure SQL Managed Instance branch; vendor guidance does not list specific fixed version numbers. Exploitation requires network access and does not require valid credentials or user interaction.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Which versions of Microsoft Azure SQL Managed Instance are affected?

BRANCHAFFECTEDFIXED
Azure SQL Managed Instance-

Is CVE-2026-62836 being exploited?

There are no public reports of active exploitation as of 2026-09-29 and it is not listed on the CISA Known Exploited Vulnerabilities catalog; no public exploit code is available.

How to fix CVE-2026-62836

  1. Apply Microsoft’s vendor guidance or patches for Azure SQL Managed Instance as soon as Microsoft publishes fixed releases.
  2. Restrict network exposure: limit access to Azure SQL Managed Instance endpoints via firewall rules, private endpoints, and network security groups.
  3. Monitor and log unusual privilege changes and anomalous connections to Azure SQL Managed Instance, and alert on suspicious activity.
  4. Contact Microsoft support for guidance specific to your Managed Instance and verify when fixed versions are available.

Frequently asked questions

Is CVE-2026-62836 being actively exploited?

There are no public reports of exploitation and it is not listed in the CISA KEV catalog as of 2026-09-29.

Which Azure SQL Managed Instance versions are affected by CVE-2026-62836?

Microsoft lists the issue against the Azure SQL Managed Instance branch; vendor information does not specify particular fixed version numbers in the provided facts.

Is there a patch for CVE-2026-62836?

Patch availability is indicated by Microsoft’s advisory status, but the facts do not list specific fixed version numbers; apply Microsoft’s guidance and updates when they publish fixed releases for Azure SQL Managed Instance.

Does CVE-2026-62836 require authentication?

No. The vulnerability allows privilege elevation over the network without prior authentication to Azure SQL Managed Instance.

References