Description
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out-of-bounds read in Microsoft SQL Server that allows an authorized attacker to read memory beyond the intended bounds, resulting in the disclosure of internal data over the network. This is classified as a confidentiality breach and is identified as CWE-125.

Affected Systems

Affected versions include Microsoft SQL Server 2022 CU 26 and the GDR release, as well as Microsoft SQL Server 2025 CU 8 and its GDR release, all 64-bit editions. These editions are distributed across Windows Server platforms and are targeted by the described vulnerability.

Risk and Exploitability

The CVSS score is 6.5, indicating a moderate severity level. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalogue, suggesting no publicly observed exploitation. The attack vector is inferred to be network based, requiring an authorized user who can access the SQL Server instance. With such privileges, the attacker can trigger the out-of-bounds read to exfiltrate confidential data.

Generated by OpenCVE AI on September 8, 2026 at 19:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security update for CVE-2026-67389 that Microsoft publishes on the Microsoft Security Response Center update guide.
  • Restart the SQL Server service to load the updated binary.
  • Validate that the vulnerability no longer permits data disclosure by testing a privileged query and confirming that only expected results are returned.

Generated by OpenCVE AI on September 8, 2026 at 19:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Title Microsoft SQL Server Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2022
Microsoft sql Server 2025
Weaknesses CWE-125
CPEs cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2022
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T20:19:36.752Z

Reserved: 2026-07-29T14:57:03.842Z

Link: CVE-2026-67389

cve-icon Vulnrichment

Updated: 2026-09-08T20:19:30.648Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:18:22.397

Modified: 2026-09-08T21:18:25.793

Link: CVE-2026-67389

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T19:30:07Z

Weaknesses