
Found a local Elevation of Privilege in winget / App Installer: CVE-2026-68821 (CWE-269, Improper Privilege Management). A low-privileged user could elevate locally. CVSS 7.3 (High). Fixed in App Installer 1.30.80. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68821
Post summary
A local elevation of privilege vulnerability (CVE-2026-68821) in winget/App Installer has been disclosed, high severity, and is fixed in version 1.30.80; no exploit or PoC details are provided.
