Skip to content
anavem.com logoanavem.com logo
ResolvedMicrosoft SQL Server 2022High severityNewsCVE-2026-32167CVE-2026-32176Microsoft

Microsoft Patches SQL Server 2022 CU24 PolyBase EoP and SQL Injection with KB5083252

The April 2026 security update for SQL Server 2022 CU24 patches CVE-2026-32167 (PolyBase EoP to sysadmin) and CVE-2026-32176 (EoP/DoS), plus a SQL injection fix in system stored procedures. Build 16.0.4250.1.

On this page

Key takeaways

  • CVE-2026-32167: low-priv to sysadmin via PolyBase linked servers (same as SQL 2019).
  • SQL injection fix in system stored procedures.
  • Build 16.0.4250.1. File size: 464.4 MB (x64).
  • MSDASQL linked server breaking change (Msg 7416).

What to do now

High urgency
  1. Install KB5083252 or latest SQL Server 2022 CU.
  2. Test MSDASQL linked servers before production deployment.

Microsoft released KB5083252 on April 14, 2026, a security update for SQL Server 2022 CU24 patching CVE-2026-32167 (PolyBase privilege escalation to sysadmin), CVE-2026-32176, and a SQL injection flaw in system stored procedures.

The PolyBase sysadmin escalation affects both SQL Server 2019 and 2022. Organizations running either version should patch promptly.

KB5083252 patches PolyBase EoP, SQL injection, and CVE-2026-32176 in SQL Server 2022 CU24.

SQL Server 2022 CU24: PolyBase sysadmin escalation + SQL injection fix. Build 16.0.4250.1. MSDASQL breaking change.

Affected & context

Event summary

April 2026 security update for SQL Server 2022 CU24 patching PolyBase EoP and SQL injection.

Why it matters

PolyBase sysadmin escalation and SQL injection in stored procedures.

Who is affected

SQL Server 2022 RTM with any CU applied, all editions.

Vendors
Microsoft
Products
SQL Server 2022 (Windows)SQL Server 2022 (Linux)
CVEs
CVE-2026-32167CVE-2026-32176

KB5083252 Patches PolyBase EoP and SQL Injection in SQL Server 2022 CU24

Microsoft released KB5083252 on April 14, 2026, a security update for SQL Server 2022 Cumulative Update 24. The update patches CVE-2026-32167, which allows a low-privileged SQL Server user to gain sysadmin permissions through PolyBase linked servers, and CVE-2026-32176, an additional elevation of privilege vulnerability. It also fixes a SQL injection flaw in system stored procedures caused by improper neutralization of special elements. Build updates to 16.0.4250.1.

Like the parallel SQL Server 2019 update (KB5084816), this introduces the MSDASQL linked server breaking change: queries using the OLE DB Provider for ODBC Drivers with @provstr fail with Msg 7416 due to stricter connection validation.

Same PolyBase Sysadmin Escalation as SQL Server 2019

CVE-2026-32167 is the same PolyBase linked server escalation vector patched in SQL Server 2019 (KB5084816). A low-privileged database user can escalate to sysadmin, making it critical for any multi-user SQL Server environment. The SQL injection fix in system stored procedures closes an additional code execution path.

SQL Server 2022 is the current production version. Organizations running CU24 or earlier should patch immediately. File size: 464.4 MB (x64), significantly smaller than the SQL Server 2019 update.

Affected Systems and Known Issues

SQL Server 2022 RTM instances with any CU applied, on Windows and Linux. All editions (Express, Developer, Standard, Enterprise). Build 16.0.4250.1. File size: 464.4 MB.

Known issue: MSDASQL linked server

Linked server queries using MSDASQL with @provstr fail with Msg 7416 due to stricter validation. Same breaking change as SQL Server 2019 updates.

Timeline

  1. KB5083252 released

    Microsoft releases KB5083252 as April Patch Tuesday security update for SQL Server 2022 CU24.

    Source: Microsoft Support

    Confidence: High

Impact

PolyBase EoP, SQL injection, and MSDASQL breaking change in SQL Server 2022 CU24.

Business impact

PolyBase EoP enables sysadmin escalation. SQL injection in stored procedures enables code execution.

Security impact

CVE-2026-32167 allows low-privileged users to gain sysadmin via PolyBase linked servers.

Affected audience: SQL Server 2022 DBAs, Environments with PolyBase linked servers and non-admin users

Action required.

Technical details

CVEs
CVE-2026-32167, CVE-2026-32176
Attack vector
Network (authenticated)
Affected versions
SQL Server 2022 (all builds before 16.0.4250.1)
Patched versions
SQL Server 2022 Build 16.0.4250.1

Mitigations

  • Install KB5083252.
  • Restrict PolyBase and linked server permissions.

Technical references

Response

Response status: Patched

Patch available: Yes

Workaround available: No

FAQ

What does KB5083252 fix?

CVE-2026-32167 (PolyBase linked server EoP to sysadmin), CVE-2026-32176 (EoP), SQL injection in system stored procedures, and the MSDASQL linked server validation tightening. Build 16.0.4250.1.

Which systems need this update?

SQL Server 2022 RTM instances with any CU applied, all editions, on Windows and Linux.

Are there known issues?

Yes. MSDASQL linked server queries with @provstr fail with Msg 7416. Same issue as the SQL Server 2019 updates.

The bottom line

KB5083252 patches CVE-2026-32167 (PolyBase EoP to sysadmin), CVE-2026-32176, and SQL injection in system stored procedures for SQL Server 2022 CU24. Build 16.0.4250.1.

Same PolyBase sysadmin escalation as SQL Server 2019. Patch SQL Server 2022 to Build 16.0.4250.1 or install the latest available CU.

What happens next

Check for newer SQL Server 2022 CU releases that supersede this update.

What to do

Install KB5083252 or the latest SQL Server 2022 CU. Test MSDASQL linked servers before production.

Sources

  1. Microsoft · Apr 14, 2026 · Primary source

    Claims supported
    • CVE-2026-32167 PolyBase EoP
    • SQL injection fix
    • Build 16.0.4250.1
    • MSDASQL breaking change
  2. Microsoft · Apr 14, 2026 · Primary source

    Claims supported
    • 464.4 MB file size
  3. Microsoft · Apr 14, 2026 · Primary source

    Claims supported
    • Update availability
Reader actions
Was this helpful?
Rate this articleRate
2 readers viewed this article

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.