CVE-2026-32650 affects Anviz CrossChex Standard and involves a TDS7 PreLogin manipulation vulnerability that allows attackers to disable database encryption, forcing credentials to transmit in plaintext. This flaw enables unauthorized database access without authentication requirements. The vulnerability carries a CVSS score of 7.5 (HIGH) with a network-based attack vector, low complexity, and no authentication prerequisites, indicating significant confidentiality risk despite lacking integrity or availability impact. The moderate FAUCET risk score of 38.0/100 reflects the serious nature of plaintext credential exposure. Exploitation status indicates this vulnerability is not currently being leveraged in the wild, as evidenced by its absence from the Known Exploited Vulnerabilities catalog and inactive hot list status. However, the extremely low EPSS score suggests limited proof-of-concept availability or practical exploitation attempts to date, though organizations should prioritize patching given the straightforward attack methodology and high confidentiality impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:anviz:crosschex_standard:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.