CVE-2026-67383: Microsoft SQL Server Information Disclosure Vulnerability
Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.
Other sources
Microsoft SQL Server Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1135.8Patch KB5122770 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4085.5Patch KB5122769
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must already be authorized to access the affected SQL Server instance. The vulnerability is exploitable over the network and does not require user interaction.
What is the likely impact if exploited?
Successful exploitation can disclose sensitive information through SQL Server error messages. The provided assessment indicates confidentiality impact is high, with no integrity or availability impact.
Which deployments are identified as affected?
The affected software listed is Microsoft SQL Server 2025, including Microsoft SQL Server 2025 CU8.