CVE-2026-47297

Summary

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

Affected Software

VendorProductVersion RangeStatus
MicrosoftMicrosoft SQL Server 2019 (CU 32)15.0.0.0 < 15.0.4490.9affected
MicrosoftMicrosoft SQL Server 2019 (GDR)15.0.0 < 15.0.2190.7affected
MicrosoftMicrosoft SQL Server 2022 (CU 26)16.0.0.0 < 16.0.4275.2affected
MicrosoftMicrosoft SQL Server 2022 (GDR)16.0.0 < 16.0.1200.5affected
MicrosoftMicrosoft SQL Server 2025 (CU8)17.0.0.0 < 17.0.4085.5affected
MicrosoftMicrosoft SQL Server 2025 for x64-based Systems (GDR)17.0.1050.2 < 17.0.1135.8affected

Weaknesses

  • CWE-502: CWE-502: Deserialization of Untrusted Data

References