Information Exposure Through an Error Message in Microsoft SQL Server - CVE-2026-67383

 

Information Exposure Through an Error Message in Microsoft SQL Server - CVE-2026-67383

Published: September 9, 2026


Vulnerability identifier: #VU148376
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-67383
CWE-ID: CWE-209
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to generation of error messages containing sensitive information in SQL Server when handling requests over a network. A remote user can trigger an error message containing sensitive information to disclose sensitive information.

Successful exploitation could allow reading portions of process memory.


Affected software

Microsoft SQL Server

How to mitigate CVE-2026-67383

Install security update from vendor's website.

Microsoft SQL Server - addressed in versions 17.0.1135.8, 17.0.4085.5

External References

Related Security Bulletins