CVE-2026-65669
Microsoft SQL Server Management Studio 22 injection lets unauthenticated attackers elevate privileges over the network (CVE-2026-65669)
Microsoft SQL Server Management Studio 22 before 22.8.2 has a critical injection flaw (CVSS 9.6) that allows an unauthenticated attacker to elevate privileges over the network with user interaction. Update to 22.8.2.
What happened
Microsoft describes CVE-2026-65669 as improper neutralisation of special elements in output used by a downstream component, an injection weakness (CWE-74) in SQL Server Management Studio 22. The flaw is reachable over the network, requires no prior authentication, but does require user interaction before an attacker can elevate privileges. The CVSS 3.1 vector gives a score of 9.6 critical and marks the scope as changed, meaning a successful compromise may affect resources beyond the vulnerable component with high impacts to confidentiality, integrity and availability.
At the time of writing, Microsoft has not stated active exploitation, and the CVE is not listed in CISA's Known Exploited Vulnerabilities catalogue. The CVE record also does not show public disclosure.
Who is affected
SQL Server Management Studio 22 is affected from version 22.0 up to, but not including, 22.8.2. Version 22.8.2 is the fixed release. Check every workstation or administrative machine where SQL Server Management Studio 22 is installed and can reach SQL Server instances.
What to do now
- Update SQL Server Management Studio 22 to version 22.8.2, the fixed release listed in Microsoft's September 2026 advisory. See the Microsoft advisory.
- Confirm the update across every machine where SQL Server Management Studio 22 is installed; treat version 22.8.2 as the baseline for this CVE.
- Microsoft has not published a workaround. If the update must be delayed, limit where SQL Server Management Studio 22 is used and restrict access to accounts that genuinely need the tool.
How to detect it
Microsoft has not published indicators of compromise for this CVE. Exposure is best identified through software inventory: any SQL Server Management Studio 22 installation below 22.8.2 is affected and should be treated as an update gap. If patching is incomplete, monitor SQL Server instances managed by affected installations for unexpected privilege changes.
Beyond the patch
Because this flaw is reachable over the network without prior authentication, the practical risk depends on where SQL Server Management Studio 22 is installed and what it can reach. Virtual CISO Services can help build the exposure management discipline to find those installations and prioritise the update. If an attacker does abuse the elevation of privilege, Managed Detection & Response is positioned to detect the credential abuse or lateral movement that follows.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| SQL Server Management Studio 22 | 22.0 – < 22.8.2 | 22.8.2 |