External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
SQL Server Remote
Exploit
CVE-2026-40370
Microsoft MSRC
Refer to CVE-2026-40370 NVD advisory