CVE-2026-67389: Microsoft SQL Server Information Disclosure Vulnerability
Microsoft SQL Server Information Disclosure Vulnerability
Other sources
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4275.2Patch KB5122768 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1135.8Patch KB5122770 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4085.5Patch KB5122769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1200.5Patch KB5122771
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker must be authorized, meaning they need existing authenticated access to the affected SQL Server. Exploitation can be performed over the network and does not require user interaction.
What is the expected impact if exploitation succeeds?
The vulnerability can disclose information through an out-of-bounds read. The supplied severity vector indicates high confidentiality impact, with no stated integrity or availability impact.
Which SQL Server releases are identified as affected?
The listed software includes Microsoft SQL Server 2022, Microsoft SQL Server 2022 CU 26, Microsoft SQL Server 2025, and Microsoft SQL Server 2025 CU8.