
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32214 is an improper access control vulnerability in the Windows Universal Plug and Play service (upnp.dll) that allows a low-privileged local attacker to disclose sensitive information. Disclosed on April 14, 2026, as part of Microsoft's April 2026 Patch Tuesday, it affects a broad range of Windows versions including Windows 10 (1607 through 22H2), Windows 11 (23H2 through 26H1), Windows Server 2012 through 2025, and their Server Core variants. It carries a CVSS v3.1 base score of 5.5 (Medium) (Microsoft MSRC, GitHub Advisory).
The vulnerability is classified as CWE-284 (Improper Access Control) and resides in upnp.dll, the Windows UPnP service library. Due to insufficient access restrictions, an authorized but low-privileged local user can access resources or data that should be protected, resulting in unintended information disclosure. Exploitation requires local access and low privileges, with no user interaction needed, and the attack complexity is low. No public technical write-ups or proof-of-concept code have been identified at this time (Microsoft MSRC, GitHub Advisory).
Successful exploitation results in a high confidentiality impact — a low-privileged local attacker can read sensitive system information that should be inaccessible to them. There is no impact to integrity or availability. While the vulnerability is limited to local access and does not directly enable code execution or lateral movement, the disclosed information could potentially be leveraged to facilitate further attacks on the affected system (Microsoft MSRC).
No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.035–0.045%, placing it in the 14th percentile for exploitation likelihood within 30 days. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory, Feedly).
Microsoft released patches on April 14, 2026, addressing this vulnerability across all affected Windows versions. Administrators should apply the relevant cumulative updates to reach the following minimum build versions:
As a workaround, organizations should consider disabling the UPnP service if it is not required for business operations, and enforce the principle of least privilege to limit local user access (Microsoft MSRC).
CVE-2026-32214 was covered as part of broader April 2026 Patch Tuesday roundups. BleepingComputer reported on the full release of 167 fixes including this vulnerability, and Zero Day Initiative (ZDI) published its April 2026 security update review. Rapid7 also included it in their Patch Tuesday analysis. No significant standalone commentary or social media discussion specific to this CVE has been identified, consistent with its moderate severity and lack of active exploitation (BleepingComputer, ZDI, Rapid7).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."