Description
Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient logging in SQL Server creates a pathway for an attacker with authorized credentials to evade a security feature over a network. The flaw allows the attacker to bypass enforcement controls that normally restrict certain operations, potentially undermining database integrity and compliance. This vulnerability is grounded in CWE-778 and is limited to situations where the attacker can authenticate to the system normally.

Affected Systems

Affected systems include Microsoft SQL Server 2022 version CU 26 and the GDR release, and Microsoft SQL Server 2025 version CU 8 and the x64‑based GDR release. Administrators should confirm the presence of these component versions within their environment.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score is currently unavailable, but the lack of listing in the CISA KEV catalog suggests limited widespread exploitation to date. The likely attack vector is a network‑based interaction from an authenticated user; the attacker must have legitimate access to the database engine to exploit the bypass. Because the flaw allows direct bypass of a security feature rather than arbitrary code execution, the risk is confined to the scope of the compromised database instance and its associated permissions.

Generated by OpenCVE AI on September 8, 2026 at 19:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest cumulative update or security patch for each affected SQL Server version, as listed on the Microsoft Security Update Guide.
  • Protect privileged accounts by restricting local access and enforcing strict role‑based permissions to reduce the window for an authorized attacker to exploit the bypass.
  • Enable comprehensive audit logging for rule enforcement to detect and respond to any attempts to bypass security controls.

Generated by OpenCVE AI on September 8, 2026 at 19:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.
Title Microsoft SQL Server Security Feature Bypass Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2022
Microsoft sql Server 2025
Weaknesses CWE-778
CPEs cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2022
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T18:35:17.186Z

Reserved: 2026-07-27T19:02:26.601Z

Link: CVE-2026-66816

cve-icon Vulnrichment

Updated: 2026-09-08T18:24:18.665Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:18:20.010

Modified: 2026-09-08T19:18:08.633

Link: CVE-2026-66816

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T19:30:07Z

Weaknesses