CVE-2026-32194

Published Mar 19, 2026

Last updated 3 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-32194 is a command injection vulnerability found in Microsoft Bing Images. This flaw stems from the improper neutralization of special elements within a command, which allows an unauthorized attacker to execute code. The vulnerability is specifically reachable through the public "Search by Image" upload feature. Discovered by the security firm XBOW, this vulnerability enabled attackers to execute code on Microsoft's production servers. It is related to the image processing pipeline within Bing Images.

Description
Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.
Source
secure@microsoft.com
NVD status
Analyzed
CNA Tags
exclusively-hosted-service
Products
bing_images

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

secure@microsoft.com
CWE-77

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.