Junglewise Threat Intelligence

CVE-2026-67383: Microsoft SQL Server sensitive information disclosure in error messages

CVE-2026-67383 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Technologies: Microsoft SQL Server. Vendors: Microsoft.

Executive brief

SQL Server can generate error messages that inadvertently expose sensitive information. An authorized attacker with network access could exploit this to extract confidential data through error responses, potentially compromising database credentials, configuration details, or other sensitive operational information.

Technical details

This vulnerability exists in SQL Server's error handling mechanism, which generates error messages containing sensitive information that should not be disclosed. The vulnerability is triggered during network communication and requires an attacker to be authorized to connect to SQL Server. By crafting specific queries or requests that generate errors, an attacker can extract sensitive data from the error message responses. No public exploit code is known to be in active circulation. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft SQL Server

Timeline

  • 2026-09-08: disclosed

References

Related threats