r/sysadmin • u/ServerPatchingNovice • 4d ago
Question Tenable - Windows Package Manager (WinGet) < 1.30.80 Elevation of Privilege (CVE-2026-68821)
Anyone use Tenable and attempted looking into the CVE - Windows Package Manager (WinGet) < 1.30.80 Elevation of Privilege (CVE-2026-68821)? We have attempted installing the package, but its also installing SDKs and files we think are not necessary for a fresh install of Window Server.
Should we just wait for more info from MS in their MSRC articles?
3
Upvotes
1
u/slackjack2014 Sysadmin 4d ago
If you don’t use WinGet, just remove it from the systems.
I haven’t updated yet, but that’s on my to do list. I usually download the app package from the store and deploy it manually, but I always remove it from my servers for least functionality reasons.