CVE-2026-62836

azure_sql_managed_instance: Improper Restriction of Communication Channel to Intended Endpoints (CVE-2026-62836)

criticalEPSS 0.4 %

Beschreibung

Ungenaue Einschränkung des Kommunikationskanals auf die vorgesehenen Endpunkte in der Azure SQL Managed Instance ermöglicht es einem nicht autorisierten Angreifer, über ein Netzwerk Berechtigungen zu erhöhen.

Metriken

Severity
critical
kein öffentlicher PoC bekannt
10.0
Quelle: nvd-v3
36.7 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.4 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-06 22:37 UTC
CWE-923

Weakness-Klassen (CWE)

  • CWE-923Class

    Improper Restriction of Communication Channel to Intended Endpoints

    The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-08-11 16:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-62836","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…{"id":"CVE-2026-62836","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  2. CVE Modified2026-08-08 05:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-62836","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…{"id":"CVE-2026-62836","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
  3. Initial Analysis2026-08-07 19:02 UTC· nvd@nist.gov
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
    • CPE Configuration: OR *cpe:2.3:a:microsoft:azure_sql_managed_instance:-:*:*:*:*:*:*:*
    • Reference Type: Microsoft Corporation: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62836 Types: Vendor Advisory
  4. CVE Modified2026-08-07 18:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-62836","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  5. New CVE Received2026-08-07 00:16 UTC· secure@microsoft.com
    • Affected: Azure SQL Managed Instance
    • Tag: exclusively-hosted-service
    • Description: Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
    • CVSS V3.1: AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • microsoft

    azure_sql_managed_instance

Quellen & Referenzen

Verknüpfte Empfehlungen

IDCVE-2026-62836