Description
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

Based on the description, it is inferred that an authorized attacker with authenticated access to the SQL Server instance can read internal memory and transmit the leaked data over the network. The flaw is a classic bounds‑checking failure, classified as CWE‑125, and could expose sensitive database contents or configuration information to such an attacker.

Affected Systems

Microsoft SQL Server 2017 on the 64‑bit platform when the cumulative update is at CU 31 or the GDR, Microsoft SQL Server 2019 at CU 32 or the GDR, Microsoft SQL Server 2022 at CU 26 or the GDR, and Microsoft SQL Server 2025 at CU 8 or the GDR for x64‑based installations.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. The EPSS score indicates a very low probability of exploitation (<1%), and the vulnerability is not listed in CISA’s KEV catalog. An attacker must already possess valid credentials to the database engine, so the attack surface is limited to authenticated users or compromised accounts. Because the flaw permits remote disclosure of memory contents rather than code execution, the threat primarily centers on data exposure rather than service disruption. Patching or upgrading mitigates the risk.

Generated by OpenCVE AI on September 10, 2026 at 03:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Microsoft SQL Server to a release that contains the fix for CVE‑2026‑68781, such as applying the latest cumulative update or GDR for the affected version.
  • Limit database network exposure by restricting inbound connections to trusted hosts and enabling firewall rules that block unauthorized traffic.
  • Ensure that database users operate with the principle of least privilege so that even if an attacker gains access, the scope of readable data is minimized.

Generated by OpenCVE AI on September 10, 2026 at 03:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:*

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Title Microsoft SQL Server Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
Weaknesses CWE-125
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sql Server 2017 Sql Server 2019 Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:30:38.854Z

Reserved: 2026-07-31T16:33:08.215Z

Link: CVE-2026-68781

cve-icon Vulnrichment

Updated: 2026-09-08T18:24:48.164Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:18:25.720

Modified: 2026-09-15T19:57:03.643

Link: CVE-2026-68781

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T23:15:18Z

Weaknesses