Junglewise Threat Intelligence

CVE-2026-67368: Microsoft SQL Server improper link resolution privilege escalation

CVE-2026-67368 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Microsoft SQL Server. Vendors: Microsoft.

Executive brief

SQL Server is a widely-deployed database platform used across enterprises to store and manage critical business data. A vulnerability in how SQL Server resolves file links allows an authenticated attacker with network access to bypass security controls and gain elevated privileges, potentially leading to unauthorized access to sensitive data or system compromise.

Technical details

The vulnerability is a link following (improper link resolution before file access) flaw in SQL Server. An authorized attacker with network connectivity to an affected SQL Server instance can exploit this to escalate their privileges. The flaw allows an attacker to manipulate file path resolution to access resources they should not have permission to reach. This is a network-accessible privilege escalation requiring valid authentication to the SQL Server instance. A patch from Microsoft is expected to be available through standard security updates.

Affected products

  • Microsoft SQL Server

Timeline

  • 2026-09-08: disclosed

References

Related threats