Encryption Weakness in Anviz CrossChex Standard Product
CVE-2026-32650

7.5HIGH

Key Information:

Vendor

Anviz

Vendor
CVE Published:
17 April 2026

What is CVE-2026-32650?

Anviz CrossChex Standard presents a security vulnerability wherein an attacker can manipulate the TDS7 PreLogin process to disable encryption. This flaw allows sensitive database credentials to be transmitted in plaintext, thereby facilitating unauthorized access to the database. Organizations utilizing this product should take immediate action to safeguard against potential exploitation by restricting access and reviewing configurations.

Affected Version(s)

Anviz CrossChex Standard All versions

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.