Description
Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: 1.0% Low
KEV: No
Impact: Privilege Escalation
Action: Patch Now
AI Analysis

Impact

An improper link resolution before file access (link following) in Microsoft SQL Server allows an authorized attacker to elevate privileges over a network. The flaw permits a user with sufficient permissions within the database environment to gain higher-level rights on the SQL Server host, potentially enabling full control over the database, unauthorized data exfiltration, or system compromise. The vulnerability is classified as CWE‑59, reflecting a flaw that permits directory traversal or symbolic link attacks. Based on the description, it is inferred that an attacker who already has authorized access within the database environment could exploit this flaw to gain higher-level rights on the host.

Affected Systems

Affected products are Microsoft SQL Server 2017 (Cumulative Update 31 and GDR), 2019 (Cumulative Update 32 and GDR), 2022 (Cumulative Update 26 and GDR), and 2025 (Cumulative Update 8 and GDR) on x64-based systems.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, and the EPSS score of <1% shows a very low probability of exploitation at this time. The issue is not listed in the CISA KEV catalog. The flaw can be exploited by an attacker who already has authorized access to the SQL Server environment and can act over a network to obtain elevated privileges. Based on the description, it is inferred that the likely attack vector is a network-based exploitation from within the same database environment.

Generated by OpenCVE AI on September 10, 2026 at 03:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Microsoft SQL Server security update that addresses CVE‑2026‑67368 for all affected instances.
  • Restart all SQL Server services after installing the patch to ensure the updated binaries and configuration are active.
  • As a temporary containment measure, limit network access to the SQL Server instances, enforce strict file system permissions, and avoid exposing privileged accounts or shared directories to untrusted network segments.

Generated by OpenCVE AI on September 10, 2026 at 03:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:*

Fri, 11 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.
Title Microsoft SQL Server Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
Weaknesses CWE-59
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sql Server 2017 Sql Server 2019 Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:30:35.336Z

Reserved: 2026-07-29T14:57:03.840Z

Link: CVE-2026-67368

cve-icon Vulnrichment

Updated: 2026-09-09T10:04:49.996Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:18:20.550

Modified: 2026-09-15T18:56:31.803

Link: CVE-2026-67368

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T03:30:17Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')