Record summary

CVE-2026-32214 has a selected CVSS score of 5.5 (medium).

Description

Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

Description source: GitHub Advisory

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 14, 2026 · Source: CVE List

Affected products and versions

Showing 12 of 21
ProductSourceVersion rangeStatus
CVE List10.0.14393.0 to < 10.0.14393.9060affected
CVE List10.0.17763.0 to < 10.0.17763.8644affected
CVE List10.0.19044.0 to < 10.0.19044.7184affected
CVE List10.0.19045.0 to < 10.0.19045.7184affected
CVE List10.0.22631.0 to < 10.0.22631.6936affected
CVE List10.0.26100.0 to < 10.0.26100.8246affected
CVE List10.0.26200.0 to < 10.0.26200.8246affected
CVE List10.0.22631.0 to < 10.0.22631.6936affected
CVE List10.0.28000.0 to < 10.0.28000.1836affected
CVE List6.2.9200.0 to < 6.2.9200.26026affected

Windows Server 2012 (Server Core installation)

Browse Microsoft / Windows Server 2012 (Server Core installation)
CVE List6.2.9200.0 to < 6.2.9200.26026affected
CVE List6.3.9600.0 to < 6.3.9600.23132affected

References

2