Description
Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-07-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a type‑confusion flaw in Microsoft SQL Server 2025. It allows an attacker who already has authorized access to the server to read data that the server does not intend to expose, effectively leaking confidential information across the network. The weakness, classified as CWE‑843, does not provide a path to alter data, execute arbitrary code, or impact availability.

Affected Systems

Microsoft SQL Server 2025 (CU 6) and Microsoft SQL Server 2025 for x64‑based systems (GDR) are the affected products. The CNA lists these two specific releases with no further version exclusions, meaning any instance of either release that has not been updated is vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1 % shows that exploitation is unlikely in the wild. The vulnerability is not currently recorded in the CISA KEV catalog. An attacker must be authenticated against the database engine; there is no privilege escalation or code‑execution side‑channel. The attack vector is thus network‑based information disclosure through equivalent or higher‑privileged credentials.

Generated by OpenCVE AI on August 1, 2026 at 09:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft security update for SQL Server 2025 CU 6 and the GDR release as published by Microsoft.
  • Enforce network segmentation and firewall rules to limit inbound connections to the database hosts.
  • Apply least‑privilege and strong authentication policies to all accounts with database access.
  • Disable or restrict database features and stored procedures that could trigger the type‑confusion flaw.

Generated by OpenCVE AI on August 1, 2026 at 09:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Sql Server 2025 (cu 2)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)
Vendors & Products Microsoft microsoft Sql Server 2025 (cu 2)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)

Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network.
Title Microsoft SQL Server Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2025
Weaknesses CWE-843
CPEs cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Microsoft Sql Server 2025 (cu 2) Microsoft Sql Server 2025 For X64-based Systems (gdr) Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:26:44.448Z

Reserved: 2026-06-11T20:33:37.835Z

Link: CVE-2026-54116

cve-icon Vulnrichment

Updated: 2026-07-16T14:16:15.655Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:45:03Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')