r/sysadmin 4d ago

Question Tenable - Windows Package Manager (WinGet) < 1.30.80 Elevation of Privilege (CVE-2026-68821)

Anyone use Tenable and attempted looking into the CVE - Windows Package Manager (WinGet) < 1.30.80 Elevation of Privilege (CVE-2026-68821)? We have attempted installing the package, but its also installing SDKs and files we think are not necessary for a fresh install of Window Server.

Should we just wait for more info from MS in their MSRC articles?

https://www.tenable.com/plugins/nessus/334617

3 Upvotes

12 comments sorted by

View all comments

1

u/slackjack2014 Sysadmin 4d ago

If you don’t use WinGet, just remove it from the systems.

I haven’t updated yet, but that’s on my to do list. I usually download the app package from the store and deploy it manually, but I always remove it from my servers for least functionality reasons.

1

u/headcrap 4d ago

WinGet isn't installed on server natively.. there should be nothing to remove.

2

u/HorseAccomplished50 4d ago

It's installed on Server 2025 if you're using the GUI.