CVE-2026-69562: Microsoft SQL Server Information Disclosure Vulnerability
Microsoft SQL Server Information Disclosure Vulnerability
Other sources
Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4490.9Patch KB5122772 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3550.4Patch KB5122774 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2190.7Patch KB5122773 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2130.4Patch KB5122775
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The vulnerability is network-reachable and requires no privileges, but it does require user interaction. Successful exploitation can disclose information; integrity and availability impact are not indicated.
Which SQL Server deployments are identified as affected?
The affected software list includes Microsoft SQL Server 2017, SQL Server 2017 CU 31, SQL Server 2019, and SQL Server 2019 CU 32.