VDB

GCVE-110-NCSC-2026-232

GCVE-110-NCSC-2026-232
Advisory PublishedCVSS 7.8/10
Vulnetix · Advisory published July 14, 2026
Improper neutralization of special elements in SQL Server commands, known as SQL injection, allows an authorized attacker to locally elevate privileges within the system.

Weaknesses (CWE)

CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-502Deserialization of Untrusted DataCWE-73External Control of File Name or PathCWE-126Buffer Over-readCWE-843Access of Resource Using Incompatible Type ('Type Confusion')CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-121Stack-based Buffer Overflow

Risk Scores

CVSS 3.1
7.8/10
High · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
Microsoftvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

75,874 records in the GCVE database · Updated August 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›