Junglewise Threat Intelligence

CVE-2026-67624: Microsoft SQL Server out-of-bounds read information disclosure

CVE-2026-67624 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Technologies: Microsoft SQL Server. Vendors: Microsoft.

Executive brief

SQL Server, Microsoft's enterprise database platform, contains an out-of-bounds read vulnerability that allows an authorized user to read memory contents and extract sensitive information over the network. While this requires an existing database login, an attacker with credentials could potentially access data beyond their intended permissions or retrieve system secrets.

Technical details

An out-of-bounds read vulnerability exists in SQL Server's memory handling, allowing an authenticated attacker to read unintended memory regions. The vulnerability requires network access and valid database credentials; an attacker must be able to connect to SQL Server and execute queries. By crafting specific queries, the attacker can leak information from server memory, potentially exposing encryption keys, other users' data, or other sensitive information. A security update from Microsoft is available to remediate this issue.

Affected products

  • Microsoft SQL Server

Timeline

  • 2026-09-08: disclosed

References

Related threats