Windows Package Manager 1.29.290 Seals Privilege Escalation Flaws, Stabilizes v1.29 Features

Published by

Windows Package Manager 1.29.290 was released on August 24, 2026, focusing on addressing two privilege escalation vulnerabilities in the uninstall workflow while maintaining the features from version 1.29. The update prevents elevated admin tokens from bypassing user-scoped package boundaries during uninstallation, thereby enhancing security. The new build stabilizes existing features, including the experimental Source Priority capability, without adding any new functionalities. Users can obtain the update via the Microsoft Store or GitHub, and it is compatible with Windows 10 version 1809 and later



Windows Package Manager 1.29.290 Seals Privilege Escalation Flaws, Stabilizes v1.29 Features

Windows Package Manager reached v1.29.290 on August 24, 2026, with a release focused primarily on closing two privilege escalation vectors in the uninstall workflow. The build inherits the v1.29 feature set, including the experimental Source Priority capability and new MCP server parameters that let AI agents trigger package upgrades. A single contributor merged two pull requests that patch edge cases where elevated admin tokens or disabled UAC could bypass user-scoped package boundaries. You can pick up the update via the Microsoft Store or GitHub, though the Source Priority flag still sits behind experimental settings until you enable it in your config.

Windows Package Manager 1.29.290 Seals Privilege Escalation Flaws, Stabilizes v1.29 Features @ NT Compatible