Description
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds read in Microsoft SQL Server that permits an authorized attacker to read memory contents and disclose sensitive data over the network. This flaw arises from improper bounds checking during data handling, classified as CWE-125. An attacker who can authenticate to the SQL Server instance can therefore obtain confidential information that was not intended to be exposed, leading to a confidentiality breach.

Affected Systems

Affected systems include Microsoft SQL Server 2017 released as 31st cumulative update or the GDR release; Microsoft SQL Server 2019 released as 32nd cumulative update or the GDR release; Microsoft SQL Server 2022 released as 26th cumulative update or the GDR release; and Microsoft SQL Server 2025 released as 8th cumulative update or the GDR release for x64-based systems. These updates are available for the x64 architecture as listed in the CNA affected-product data.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity. EPSS is not available, so the probability of exploitation cannot be quantified at this time, and the vulnerability is not listed in the CISA KEV catalog. The flaw requires that the attacker already have authorized access to the database engine; therefore the attack vector is likely by an authenticated network user. An adversary could read arbitrary memory contents that may contain passwords, cryptographic keys, or other sensitive data, which could facilitate further compromise or insider threats. No public exploits are known.

Generated by OpenCVE AI on September 8, 2026 at 19:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest cumulative update or GDR for your SQL Server release from Microsoft, as detailed in the MSRC update guide.
  • Restart the SQL Server service to load the updated binaries.
  • Disable any redundant or unnecessary extensions and features on the server to reduce the attack surface.

Generated by OpenCVE AI on September 8, 2026 at 19:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Title Microsoft SQL Server Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
Weaknesses CWE-125
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sql Server 2017 Sql Server 2019 Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T20:17:23.528Z

Reserved: 2026-07-31T16:33:08.214Z

Link: CVE-2026-68777

cve-icon Vulnrichment

Updated: 2026-09-08T20:17:16.917Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:18:25.197

Modified: 2026-09-08T21:18:26.480

Link: CVE-2026-68777

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T19:45:05Z

Weaknesses