Vulnerability Details CVE-2026-54116
Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 57.6%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-54116
-
cpe:2.3:a:microsoft:sql_server_2025:17.0.1000.7
-
cpe:2.3:a:microsoft:sql_server_2025:17.0.1050.2
-
cpe:2.3:a:microsoft:sql_server_2025:17.0.1105.2
-
cpe:2.3:a:microsoft:sql_server_2025:17.0.1110.1
-
cpe:2.3:a:microsoft:sql_server_2025:17.0.1115.1
-
cpe:2.3:a:microsoft:sql_server_2025:17.0.4006.2
-
cpe:2.3:a:microsoft:sql_server_2025:17.0.4020.2
-
cpe:2.3:a:microsoft:sql_server_2025:17.0.4030.1
-
cpe:2.3:a:microsoft:sql_server_2025:17.0.4040.1