CVE-2026-32176 — SQL Injection in Microsoft SQL Server 2016 Service Pack 3
Severity
6.7MEDIUMNVD
EPSS
0.1%
top 78.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 14
Description
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9
Affected Packages8 packages
🔴Vulnerability Details
3GHSA▶
GHSA-vfhv-wjq9-p5qh: Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges↗2026-04-14