vulnti.work

Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.

Medium CVSS 5.5
CVECVE-2026-69351
First seen2026-09-17 18:01 UTC
Disclosed2026-09-08 18:18 UTC
Last updated2026-09-17 18:01 UTC
Channel statusauto

Summary

Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.

In-depth triage

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Affected products

  • :

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD