CVE-2026-67390: Microsoft SQL Server Information Disclosure Vulnerability
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Other sources
Microsoft SQL Server Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4085.5Patch KB5122769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4275.2Patch KB5122768 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1135.8Patch KB5122770 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4490.9Patch KB5122772 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3550.4Patch KB5122774 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1200.5Patch KB5122771 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2190.7Patch KB5122773 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2130.4Patch KB5122775
Event History
Frequently Asked Questions
What level of access does an attacker need?
The attacker must be authorized, meaning they need low-privileged access to SQL Server. Exploitation can occur over the network and does not require user interaction.
What is the expected security impact?
The issue can disclose information because of a buffer over-read. The provided severity data indicates high confidentiality impact, with no indicated integrity or availability impact.
Which SQL Server releases are identified?
The listed software includes Microsoft SQL Server 2017, 2019, 2022, and 2025, including SQL Server 2017 CU31, SQL Server 2019 CU32, SQL Server 2022 CU26, and SQL Server 2025 CU8.