CVE-2026-32167 PUBLISHED CVSS 6.699999809265137 MEDIUM

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

Risk Scores

CVSS v3.1
6.699999809265137
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Affected Products

VendorProductVersions
MicrosoftMicrosoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack13.0.0
microsoftsql_server_202517.0.1050.2, 17.0.4030.1
MicrosoftMicrosoft SQL Server 2019 (GDR)15.0.0
microsoftsql_server_201613.0.0, 13.0.0
MicrosoftMicrosoft SQL Server 2025 (CU 3)17.0.4030.1
microsoftsql_server_201714.0.0, 14.0.0
microsoftsql_server_201915.0.0.0, 15.0.0
MicrosoftMicrosoft SQL Server 2017 (CU 31)14.0.0
MicrosoftMicrosoft SQL Server 2025 for x64-based Systems (GDR)17.0.1050.2
MicrosoftMicrosoft SQL Server 2019 (CU 32)15.0.0.0
MicrosoftMicrosoft SQL Server 2022 for x64-based Systems (CU 24)16.0.0.0
MicrosoftMicrosoft SQL Server 2016 Service Pack 3 (GDR)13.0.0
microsoftsql_server_202216.0.0, 16.0.0.0
MicrosoftMicrosoft SQL Server 2017 (GDR)14.0.0
MicrosoftMicrosoft SQL Server 2022 (GDR)16.0.0

Timeline

References

…and 1 more

Open in Interactive Console →