CVE-2026-66816: Microsoft SQL Server Security Feature Bypass Vulnerability
Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.
Other sources
Microsoft SQL Server Security Feature Bypass Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1200.5Patch KB5122771 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1135.8Patch KB5122770 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4085.5Patch KB5122769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4275.2Patch KB5122768
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must already be authorized to access the affected SQL Server instance. Exploitation can be performed over the network and does not require user interaction.
What is the potential impact?
The issue may allow an authorized attacker to bypass a SQL Server security feature because of insufficient logging. The listed impact includes high confidentiality impact, with no integrity or availability impact indicated.
Which SQL Server releases are identified as affected?
The affected software list includes Microsoft SQL Server 2025, Microsoft SQL Server 2022, Microsoft SQL Server 2022 CU 26, and Microsoft SQL Server 2025 CU8.