CVE-2026-66816: Microsoft SQL Server Security Feature Bypass Vulnerability
Overview
- Severity
- Medium (CVSS 6.5)
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
- Category
- Security Feature Bypass
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2026-Sep
- Released
- 2026-09-08
Description
Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.
FAQ
What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker could bypass the logging of downloaded files.
Affected Products (4)
SQL Server
- Microsoft SQL Server 2022 for x64-based Systems (GDR)
- Microsoft SQL Server 2025 for x64-based Systems (GDR)
- Microsoft SQL Server 2025 for x64-based Systems (CU8)
- Microsoft SQL Server 2022 for x64-based Systems (CU 26)
Security Updates (4)
Acknowledgments
<a href="https://www.linkedin.com/in/fabianoamorim/">Fabiano Amorim</a> with <a href="https://pythian.com/">Pythian</a>
Revision History
- 2026-09-08: Information published.