Junglewise Threat Intelligence

CVE-2026-67393: Microsoft SQL Server buffer over-read information disclosure

CVE-2026-67393 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Technologies: Microsoft SQL Server. Vendors: Microsoft.

Executive brief

SQL Server, a widely-used enterprise database platform, contains a buffer over-read vulnerability that could allow an authorized attacker to read sensitive data across the network. This vulnerability requires valid database credentials to exploit, limiting exposure primarily to insider threats or attackers who have already compromised legitimate access. Successful exploitation could result in unauthorized disclosure of confidential information stored in the database.

Technical details

A buffer over-read vulnerability exists in Microsoft SQL Server that permits an authenticated attacker to disclose information over the network. The vulnerability is a memory safety issue where improperly bounded buffer access allows reading beyond intended memory regions. Exploitation requires valid SQL Server authentication credentials and network connectivity to the database server. An attacker with legitimate database access can craft specific requests to trigger the over-read and exfiltrate sensitive data. Patches are available from Microsoft via their security update process.

Affected products

  • Microsoft SQL Server

Timeline

  • 2026-09-08: disclosed

References

Related threats