Information Disclosure Vulnerability in Microsoft SQL Server by Microsoft
CVE-2026-67386
6.5MEDIUM
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-67386?
A vulnerability exists in Microsoft SQL Server that stems from the improper handling of uninitialized resources. This flaw can be exploited by an authenticated attacker, enabling them to disclose sensitive information over a network. Effective mitigation requires prompt attention to security updates and patches released by Microsoft.
Affected Version(s)
Microsoft SQL Server 2017 (CU 31) x64-based Systems 14.0.0 < 14.0.3550.4
Microsoft SQL Server 2017 (GDR) x64-based Systems 14.0.0 < 14.0.2130.4
Microsoft SQL Server 2019 (CU 32) x64-based Systems 15.0.0.0 < 15.0.4490.9