CVE-2026-68776: Microsoft SQL Server Information Disclosure Vulnerability
Microsoft SQL Server Information Disclosure Vulnerability
Other sources
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4275.2Patch KB5122768 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3550.4Patch KB5122774 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4085.5Patch KB5122769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4490.9Patch KB5122772 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1135.8Patch KB5122770 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1200.5Patch KB5122771 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2190.7Patch KB5122773 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2130.4Patch KB5122775
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authorized to access the affected SQL Server instance. The attack can be performed over a network and does not require user interaction.
What is the potential impact?
Successful exploitation may allow disclosure of information. The supplied severity vector indicates high confidentiality impact, with no stated integrity or availability impact.
Which SQL Server releases are listed as affected?
The affected software list includes SQL Server 2017 and 2019, including CU 31 and CU 32 respectively; SQL Server 2022, including CU 26; and SQL Server 2025, including CU8.
Does the provided information indicate that default installations are affected?
No. The available information does not state whether exploitation depends on a default configuration or any specific SQL Server feature being enabled.