CVE-2026-47292 HIGH

CVE-2026-47292: Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability

Vendor Microsoft
Product Visual Studio Code - MSSQL Extension
Weakness CWE-829 · Inclusion from untrusted sphere
Published June 9, 2026
Last update June 15, 2026

CVSS base score

7.8/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

What the vulnerability does

01Description

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.

Key dates

02Disclosure timeline

June 9, 2026 CVE published
June 15, 2026 Record updated