CVE-2026-66816
Awaiting Analysis Awaiting Analysis - Queue

Insufficient Logging Bypass in SQL Server

Vulnerability report for CVE-2026-66816, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-16

Assigner: Microsoft Corporation

Description

Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-16
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
microsoft sql_server_2022 to 16.0.1200.5 (exc)
microsoft sql_server_2022 From 16.0.4003.1 (inc) to 16.0.4275.2 (exc)
microsoft sql_server_2025 to 17.0.1135.8 (exc)
microsoft sql_server_2025 From 17.0.4006.2 (inc) to 17.0.4085.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-778 When a security-critical event occurs, the product either does not record the event or omits important details about the event when logging it.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves insufficient logging in SQL Server, which allows an authorized attacker to bypass a security feature over a network. The issue does not require user interaction and can lead to high confidentiality impact as sensitive data may be accessed without detection.

Impact Analysis

An attacker could exploit this to bypass security controls and access sensitive data without leaving a trace in logs. This could result in unauthorized data exposure, data theft, or further compromise of the database environment.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to insufficient logging and potential unauthorized data access. Both regulations require robust logging and protection of personal data, which this flaw undermines.

Mitigation Strategies

Apply the latest security updates from Microsoft for SQL Server to address insufficient logging issues. Monitor network traffic for unusual SQL queries or unauthorized access attempts. Enable comprehensive logging and review logs regularly to detect bypass attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66816. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart