Skip to content
microsoftCVE-2026-85878

Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.

Critical9.9CVE-2026-85878 · Published Sep 18, 2026 · updated Sep 25, 2026

Source advisory

Affected versions

PackageAffectedFixed in
Azure HorizonDB
Vendor
all versionsNo fix yet
Details and references

Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity from
no source yet
Weakness
CWE-285

More microsoft advisories

All

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.