Junglewise Threat Intelligence

CVE-2026-54116: Microsoft SQL Server type confusion information disclosure

CVE-2026-54116 · Severity: medium · CVSS 6.5 · Published 2026-07-14

Executive brief

Microsoft SQL Server, a widely used database management system, is affected by a security vulnerability that could allow an authorized user to access sensitive information. An attacker with basic login credentials could exploit this flaw to view data they are not permitted to see, potentially compromising business confidentiality. This issue affects specific versions of SQL Server 2025 and requires the installation of security updates to resolve.

Technical details

A type confusion vulnerability (CWE-843) exists in Microsoft SQL Server 2025. The flaw occurs when the application accesses a resource using an incompatible type, which can be triggered by a remote attacker with low-level privileges (PR:L). Successful exploitation allows the attacker to disclose sensitive information over the network, though it does not grant the ability to modify data or cause a denial of service. The vulnerability affects SQL Server 2025 CU 6 and specific GDR versions for x64-based systems. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft SQL Server 2025 (CU 6) 17.0.4060.2
  • Microsoft SQL Server 2025 for x64-based Systems (GDR) 17.0.1050.2 to 17.0.1125.2

Timeline

  • 2026-07-14: advisory: Initial publication by Microsoft and NVD
  • 2026-07-14: patched: Security updates made available via MSRC update guide

References

Related threats