Junglewise Threat Intelligence

CVE-2026-69321: Microsoft Windows Power Dependency Coordinator authentication bypass

CVE-2026-69321 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Power Dependency Coordinator is a Windows system component responsible for managing power-related dependencies between services and devices. A missing authentication check allows a local attacker with existing system access to modify critical power management functions, potentially leading to system instability, denial of service, or unauthorized power state changes.

Technical details

The vulnerability is an authentication bypass in a critical function within Windows Power Dependency Coordinator, allowing unauthenticated local access to privileged operations. The attack vector is local, requiring the attacker to already have local system access. An attacker can exploit this to tamper with power management settings and dependencies, potentially causing system disruption or unauthorized power state transitions. The issue requires local execution and is not remotely exploitable from a network perspective.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats