CVE-2026-32167SQL Injection in Microsoft SQL Server 2016 Service Pack 3

CWE-89SQL Injection4 documents4 sources
Severity
6.7MEDIUMNVD
EPSS
0.1%
top 83.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14

Description

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages8 packages

CVEListV5microsoft/microsoft_sql_server_201714.0.014.0.3525.1+1
CVEListV5microsoft/microsoft_sql_server_201915.0.0.015.0.4465.1+1
CVEListV5microsoft/microsoft_sql_server_202216.0.016.0.1175.1
CVEListV5microsoft/microsoft_sql_server_202517.0.4030.117.0.4030.1
CVEListV5microsoft/microsoft_sql_server_2016_service_pack_313.0.013.0.6485.1

🔴Vulnerability Details

3
GHSA
GHSA-g255-j628-fcw3: Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges2026-04-14
CVEList
SQL Server Elevation of Privilege Vulnerability2026-04-14
VulDB
Microsoft SQL Server 2016/2017/2019/2022/2025 sql injection2026-04-14
CVE-2026-32167 — SQL Injection in Microsoft | cvebase