CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-63522: Azure SQL Database Elevation of Privilege Vulnerability

unknownCVE-2026-63522
Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.

CSIRTS triage

What
Incorrect permission assignment for critical resources allows local privilege escalation by authorized attackers.
Who is affected
Azure SQL Database deployments with permission misconfigurations are affected.
Urgency
Unknown severity (CVSS not provided) with no current exploitation reported; review permission assignments.
Action
Audit and correct permission assignments in Azure SQL Database deployments.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Azure SQL Database

Get an email when a new Azure SQL Database advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63522

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-63522coverage & exploitation statusNVD · CVE.org

Recent advisories for Azure SQL Database

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from Microsoft Security Response Center