CVE-2026-68821: Windows Package Manager Elevation of Privilege Vulnerability
Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.
Other sources
Windows Package Manager Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.30.80
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68821?
CVE-2026-68821 has a severity rating of high, with a score of 7.3.
How do I fix CVE-2026-68821?
To fix CVE-2026-68821, update your Microsoft Windows Package Manager and Microsoft App Installer to the latest version.
What systems are affected by CVE-2026-68821?
CVE-2026-68821 affects Microsoft Windows Package Manager and Microsoft App Installer.
What type of vulnerability is CVE-2026-68821?
CVE-2026-68821 is an elevation of privilege vulnerability due to improper privilege management.
Can an attacker exploit CVE-2026-68821 remotely?
No, CVE-2026-68821 requires local access for an authorized attacker to exploit the vulnerability.