azure_sql_database vulnerabilities
CVEs whose affected-version data names the azure_sql_database package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
6 CVEsRSS
CVE-2026-69502Critical· 10.0Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-68789Critical· 9.9Azure SQL Database Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
CVE-2026-68782Critical· 9.9Azure SQL Database Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
CVE-2026-66309Critical· 9.1Azure SQL Database Elevation of Privilege Vulnerability
Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
CVE-2026-63522High· 7.8Azure SQL Database Elevation of Privilege Vulnerability
Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.
CVE-2026-56162Critical· 10.0Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.