Description
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

An out‑of‑bounds read vulnerability exists in Microsoft SQL Server. The flaw allows an attacker with authorized access to send specially crafted requests that result in reading data beyond intended bounds, exposing sensitive information to the attacker over the network. Because the data is exposed, an attacker can harvest confidential strings, passwords, or other sensitive configuration data, compromising confidentiality and potentially providing a foothold for further attacks. The weakness is a classic buffer over‑read (CWE‑125).

Affected Systems

Microsoft SQL Server 2017 CU 31 and later GDR releases, 2019 CU 32 and later GDR releases, 2022 CU 26 and later GDR releases, and 2025 CU 8 and associated GDR releases on x64 systems are affected. These versions are actively supported for enterprise customers and the vulnerability was disclosed for both CU and GDR updates. Administrators should verify that the affected SQL Server instances are running a patched version.

Risk and Exploitability

The CVSS score of 6.5 reflects moderate severity, while the EPSS score is not available, indicating no publicly available data about exploitation frequency. The vulnerability is not listed in the CISA KEV catalog. Because the issue is triggered by an authorized user sending a crafted request over the network, the attack vector is network (LAN or internet) and requires an active connection to the vulnerable SQL Server. Once exploited, the attacker can read arbitrary memory content from the server, leading to disclosure of sensitive data. Mitigation relies on applying the vendor‑provided update; lacking that, limiting network exposure and enforcing strict privilege boundaries can reduce risk.

Generated by OpenCVE AI on September 8, 2026 at 19:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest cumulative update or yearly release that addresses CVE-2026-67629 for the affected SQL Server versions.
  • Restrict inbound network access to the SQL Server instance to trusted hosts, using firewall or network segmentation, to limit exposure to potential attackers.
  • Enforce the principle of least privilege by ensuring that only the minimum set of SQL Server users and service accounts have the necessary permissions, reducing the impact of any unauthorized access.

Generated by OpenCVE AI on September 8, 2026 at 19:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)
Vendors & Products Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Title Microsoft SQL Server Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
Weaknesses CWE-125
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Microsoft Sql Server 2017 (gdr) Microsoft Sql Server 2019 (gdr) Microsoft Sql Server 2022 (gdr) Microsoft Sql Server 2025 For X64-based Systems (gdr) Sql Server 2017 Sql Server 2019 Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:30:36.860Z

Reserved: 2026-07-29T22:49:19.795Z

Link: CVE-2026-67629

cve-icon Vulnrichment

Updated: 2026-09-08T20:30:35.532Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:18:23.183

Modified: 2026-09-08T21:18:26.023

Link: CVE-2026-67629

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T19:15:16Z

Weaknesses