SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-68830

MEDIUM · CVSS 5.5 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in the Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to exploit improper link resolution before file access, potentially leading to local information disclosure. Organizations using Windows systems, particularly those with UPnP enabled, should prioritize addressing this issue to mitigate the risk of unauthorized data exposure.

CVE
CVE-2026-68830
Severity
MEDIUM
CVSS
5.5
EPSS
0.29%
Windows

Original NVD Description

Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.

Related CVEs

Other vulnerabilities affecting the same vendor(s)