Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-67368 Published on September 8, 2026

Microsoft SQL Server Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.

Vendor Advisory NVD

Weakness Type

What is an insecure temporary file Vulnerability?

The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

CVE-2026-67368 has been classified to as an insecure temporary file vulnerability or weakness.


Products Associated with CVE-2026-67368

Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.

 
 
 
 

Affected Versions

Microsoft SQL Server 2017 (CU 31): Microsoft SQL Server 2017 (GDR): Microsoft SQL Server 2019 (CU 32): Microsoft SQL Server 2019 (GDR): Microsoft SQL Server 2022 (CU 26): Microsoft SQL Server 2022 (GDR): Microsoft SQL Server 2025 (CU8): Microsoft SQL Server 2025 for x64-based Systems (GDR):