Description
Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

The vulnerability is an out-of-bounds read in Microsoft SQL Server that enables an unauthenticated attacker to read memory contents. This flaw, classified as CWE‑125, can expose sensitive data stored within the database or on the host. The CVE description indicates the attacker can disclose information over a network.

Affected Systems

Microsoft SQL Server 2017 (CU 31 and GDR) and Microsoft SQL Server 2019 (CU 32 and GDR) on 64‑bit installations are affected. The issue is present in the server binaries served through the default network ports.

Risk and Exploitability

The CVSS score of 6.5 marks the vulnerability as medium severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, implying limited evidence of widespread exploitation. The attack vector is remote over the network; authentication is not required to trigger the read, allowing any host that can reach the server to potentially dissect memory. Organizations with exposed SQL Server instances face a higher risk.

Generated by OpenCVE AI on September 8, 2026 at 23:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update for CVE‑2026‑69562 from the Microsoft Security Response Center update guide.
  • If the patch is not yet available, place the SQL Server instance behind a firewall and restrict inbound network connections to trusted hosts only, preventing unauthenticated access.
  • Enable auditing and monitor for anomalous read patterns to detect attempts to read unauthorized data.

Generated by OpenCVE AI on September 8, 2026 at 23:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network.
Title Microsoft SQL Server Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Weaknesses CWE-125
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sql Server 2017 Sql Server 2019
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:05.668Z

Reserved: 2026-08-03T21:15:56.835Z

Link: CVE-2026-69562

cve-icon Vulnrichment

Updated: 2026-09-08T20:04:01.323Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:19:25.067

Modified: 2026-09-08T20:17:52.293

Link: CVE-2026-69562

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T10:15:08Z

Weaknesses