CVE-2026-67383

Summary

Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.

Affected Software

VendorProductVersion RangeStatus
MicrosoftMicrosoft SQL Server 2025 (CU8)17.0.0.0 < 17.0.4085.5affected
MicrosoftMicrosoft SQL Server 2025 for x64-based Systems (GDR)17.0.1050.2 < 17.0.1135.8affected

Weaknesses

  • CWE-209: CWE-209: Generation of Error Message Containing Sensitive Information

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References