Impact
Insufficient logging in SQL Server creates a pathway for an attacker with authorized credentials to evade a security feature over a network. The flaw allows the attacker to bypass enforcement controls that normally restrict certain operations, potentially undermining database integrity and compliance. This vulnerability is grounded in CWE-778 and is limited to situations where the attacker can authenticate to the system normally.
Affected Systems
Affected systems include Microsoft SQL Server 2022 version CU 26 and the GDR release, and Microsoft SQL Server 2025 version CU 8 and the x64‑based GDR release. Administrators should confirm the presence of these component versions within their environment.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score is currently unavailable, but the lack of listing in the CISA KEV catalog suggests limited widespread exploitation to date. The likely attack vector is a network‑based interaction from an authenticated user; the attacker must have legitimate access to the database engine to exploit the bypass. Because the flaw allows direct bypass of a security feature rather than arbitrary code execution, the risk is confined to the scope of the compromised database instance and its associated permissions.
OpenCVE Enrichment