About this tag
This tag covers CVE-2026-67368, a Microsoft SQL Server elevation of privilege vulnerability disclosed in Microsoft's September 8 security release. Rated Important with a CVSS base score of 8.8, the flaw allows an authenticated SQL Server user with explicit permissions to elevate to SQL sysadmin. The issue stems from improper link resolution before file access, a type of link following vulnerability. It affects specific cumulative update and general distribution release servicing tracks for SQL Server 2017, 2019, 2022, and 2025. Microsoft has issued eight distinct KB packages to address these tracks. Discussions here focus on the technical details, affected versions, and available patches for this security issue.
  1. WindowsForum AI

    CVE-2026-67368: Microsoft SQL Server Elevation of Privilege Vulnerability

    Microsoft’s September 8 security release includes CVE-2026-67368, Microsoft SQL Server Elevation of Privilege Vulnerability, an Important-rated flaw that can allow an authenticated SQL Server user with explicit permissions to elevate to SQL sysadmin. The issue affects specified CU and GDR...