• PATCH AVAILABLE

CVE-2026-69502: pre-auth ssrf privilege escalation in Microsoft Azure SQL Database

An unauthenticated attacker can use a server-side request forgery (SSRF) flaw to elevate privileges against Azure SQL Database, allowing remote access to internal network resources and escalation of privileges. CVE-2026-69502 is a critical vulnerability (CVSS 10.0). The advisory lists Azure SQL Database as affected; no specific fixed versions are provided in the facts. An attacker needs only network access to the service and does not require valid credentials or user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
10CRITICAL
EPSS
0.00798
CWE
CWE-918
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Treat this as urgent: the flaw permits unauthenticated remote privilege elevation (no login needed) and carries a maximum CVSS score, so immediately follow vendor guidance and reduce exposure of Azure SQL Database instances.

What is CVE-2026-69502?

An unauthenticated attacker can use a server-side request forgery (SSRF) flaw to elevate privileges against Azure SQL Database, allowing remote access to internal network resources and escalation of privileges. CVE-2026-69502 is a critical vulnerability (CVSS 10.0). The advisory lists Azure SQL Database as affected; no specific fixed versions are provided in the facts. An attacker needs only network access to the service and does not require valid credentials or user interaction. The weakness is classified as CWE-918 (Server-Side Request Forgery).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Which versions of Microsoft Azure SQL Database are affected?

BRANCHAFFECTEDFIXED
Azure SQL Database-

Is CVE-2026-69502 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-69502

  1. Follow Microsoft’s published mitigation and patch guidance for Azure SQL Database immediately.
  2. Restrict network exposure to Azure SQL Database instances (use firewalls, private endpoints, and restrict inbound access).
  3. Monitor database and network logs for suspicious outbound requests and anomalous privilege changes.
  4. Contact Microsoft support for confirmation of patch status and timeline if you cannot apply guidance promptly.

Frequently asked questions

Is CVE-2026-69502 being actively exploited?

There are no public reports of exploitation of CVE-2026-69502 as of 2026-09-29.

Which Azure SQL Database versions are affected by CVE-2026-69502?

The advisory names Azure SQL Database as affected; the facts do not list specific product versions or fixed releases.

Is there a patch for CVE-2026-69502?

A patch is reported available for this issue; the facts do not include fixed-version identifiers, so follow Microsoft’s published guidance and apply their updates.

Does CVE-2026-69502 require authentication?

No. The vulnerability can be triggered by an unauthenticated attacker and does not require valid credentials or user interaction.

References