Description
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

This vulnerability is an out‑of‑bounds read in Microsoft SQL Server that permits an attacker with authorization to the server to read memory contents that the database should not expose, resulting in the disclosure of sensitive information over the network. The weakness is a classic buffer‑overread (CWE‑125) and allows data leakage of arbitrary bytes in the process memory. If an adversary can manipulate queries or exploit the read, they may gain confidential data or keys stored in memory.

Affected Systems

Microsoft SQL Server 2017 (CU 31 and GDR), Microsoft SQL Server 2019 (CU 32 and GDR), Microsoft SQL Server 2022 (CU 26 and GDR), Microsoft SQL Server 2025 (CU 8) and Microsoft SQL Server 2025 for x64‑based Systems GDR. All of these releases target the x64 platform and are listed in the CNA data as affected products.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity risk. The EPSS score is not available, so the exploit probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, implying no documented exploits as of this analysis. Because the vulnerability requires an attacker to have valid credentials or an authorized connection to the SQL Server instance, the attack vector is inferred to be a network‑based, authenticated attack. An attacker who can issue SQL commands may use the out‑of‑bounds read to retrieve restricted memory contents, compromising data confidentiality across the affected systems.

Generated by OpenCVE AI on September 10, 2026 at 02:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft cumulative update or patch that addresses CVE-2026-68784
  • Restrict network access to SQL Server instances to trusted hosts and enforce least privilege for database users
  • Implement monitoring to detect anomalous read patterns or memory access attempts

Generated by OpenCVE AI on September 10, 2026 at 02:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Sql Server 2017 (cu 31)
Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (cu 32)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (cu 26)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 (cu8)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)
Vendors & Products Microsoft microsoft Sql Server 2017 (cu 31)
Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (cu 32)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (cu 26)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 (cu8)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:*

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Title Microsoft SQL Server Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
Weaknesses CWE-125
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Microsoft Sql Server 2017 (cu 31) Microsoft Sql Server 2017 (gdr) Microsoft Sql Server 2019 (cu 32) Microsoft Sql Server 2019 (gdr) Microsoft Sql Server 2022 (cu 26) Microsoft Sql Server 2022 (gdr) Microsoft Sql Server 2025 (cu8) Microsoft Sql Server 2025 For X64-based Systems (gdr) Sql Server 2017 Sql Server 2019 Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:30:39.472Z

Reserved: 2026-07-31T16:33:08.215Z

Link: CVE-2026-68784

cve-icon Vulnrichment

Updated: 2026-09-08T20:30:00.773Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:18:25.920

Modified: 2026-09-15T19:57:47.920

Link: CVE-2026-68784

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T23:15:18Z

Weaknesses