CVE-2026-32076 is an out-of-bounds read vulnerability in Windows Storage Spaces Controller that permits authorized local attackers to achieve privilege escalation on affected systems. The vulnerability has a CVSS severity rating of 7.8 (HIGH) with a vector of CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating that exploitation requires local access and valid credentials but no user interaction, with potential for high impact across confidentiality, integrity, and availability. The vulnerability is not currently tracked in the Known Exploited Vulnerabilities (KEV) catalog and shows no signs of active exploitation in the wild, with an EPSS score of 0.00049 indicating relatively low probability of exploitation compared to other vulnerabilities. Community attention appears limited, as the vulnerability remains on the inactive Hot List status. Organizations should prioritize patching based on their local access control posture and the presence of Windows Storage Spaces Controller in their environment, though the immediate threat level remains low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.22631.6936CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.22631.6936CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:* | ||
< 10.0.26100.8246CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.26100.8246CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:* | ||
< 10.0.26200.8246CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.