Junglewise Threat Intelligence

CVE-2026-69351: Microsoft Windows UPnP Device Host information disclosure

CVE-2026-69351 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Vendors: Microsoft.

Executive brief

Windows Universal Plug and Play (UPnP) Device Host is a system service that enables devices on a local network to discover and communicate with each other. An authorized local attacker could exploit this vulnerability to access private personal information stored or accessible through the UPnP service, potentially exposing sensitive data.

Technical details

This vulnerability is an information disclosure flaw in Windows UPnP Device Host that allows an authorized local attacker to access private personal information. The attack requires local access and authorization credentials, limiting exposure to on-premises threats. The vulnerability enables unauthorized data access within the UPnP subsystem, potentially exposing sensitive information that should be protected. Microsoft has addressed this issue through security updates for affected Windows versions.

Affected products

  • Microsoft Windows UPnP Device Host

Timeline

  • 2026-09-08: disclosed

References