microsoft / microsoft/winget-cli

2026-09 - September 8, 2026 - KB5124008 update for Windows 11 - WinGet can no longer be run in an elevated terminal (Administrator Protection enforcement)

Open
#6,497 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Command-Upgrade Issue-Bug
Dominant language
C++
Stars
26.4k
Forks
1.8k
Avg merge
1d 11h
Merged PRs (30d)
15

Description

Relevant area(s)

WinGet CLI

Relevant command(s)

winget upgrade

Brief description of your issue

after installing August 27, 2026—KB5120998 (OS Builds 26200.9278 and 26100.9278) Preview update, WinGet is no longer usable from an elevated command prompt.

Now it only works from a non-elevated terminal and requires secure-desktop approval with PIN or Password.

Steps to reproduce
  • install KB5120998 Preview update for Windows 11 Pro from Microsoft Update
Image
  • find that it now only works in non-elevated terminal windows and any upgrade action requires elevation with Windows Hello mandatory PIN/Password - a simple click on the yes button is no longer possible.
Image
Expected behavior

expected: no hidden / surprise major changes

Actual behavior

actual behaviour: KB5120998 introduces an.... interesting security context privilege separation.

Now administrator accounts seem to use a completely different user profile when elevated than when non-elevated.

Image
Environment
elevated environment:

PS C:\WINDOWS\system32> winget --info
winget : The term 'winget' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the spelling of the name, or if a path was included, verify that
 the path is correct and try again.
At line:1 char:1
+ winget --info
+ ~~~~~~
    + CategoryInfo          : ObjectNotFound: (winget:String) [], CommandNotFoundException
    + FullyQualifiedErrorId : CommandNotFoundException

PS C:\WINDOWS\system32>




non-elevated environment:
C:\>winget --info
Windows Package Manager v1.29.290
© 2026 Microsoft. All rights reserved.

Windows: Windows.Desktop v10.0.26200.9278
System Architecture: X64
Package: Microsoft.DesktopAppInstaller v1.29.290.0

WinGet Directories
-------------------------------------------------------------------------------------------------------------------------------
Logs                               %LOCALAPPDATA%\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\DiagOutputDir
User Settings                      %LOCALAPPDATA%\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\settings.json
Portable Links Directory (User)    %LOCALAPPDATA%\Microsoft\WinGet\Links
Portable Links Directory (Machine) C:\Program Files\WinGet\Links
Portable Package Root (User)       %LOCALAPPDATA%\Microsoft\WinGet\Packages
Portable Package Root              C:\Program Files\WinGet\Packages
Portable Package Root (x86)        C:\Program Files (x86)\WinGet\Packages
Installer Downloads                %USERPROFILE%\Downloads
Configuration Modules              %LOCALAPPDATA%\Microsoft\WinGet\Configuration\Modules

Links
---------------------------------------------------------------------------
Privacy Statement   https://aka.ms/winget-privacy
License Agreement   https://aka.ms/winget-license
Third Party Notices https://aka.ms/winget-3rdPartyNotice
Homepage            https://aka.ms/winget
Windows Store Terms https://www.microsoft.com/en-us/storedocs/terms-of-sale

Admin Setting                             State
--------------------------------------------------
LocalManifestFiles                        Disabled
BypassCertificatePinningForMicrosoftStore Disabled
InstallerHashOverride                     Disabled
LocalArchiveMalwareScanOverride           Disabled
ProxyCommandLineOptions                   Disabled
ConfigurationProcessorPath                Disabled
DefaultProxy                              Disabled

C:\>

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing winget --info and winget upgrade in elevated and non-elevated terminals after installing KB5120998, using the environment details in the report. Compare the command availability, profile paths, and elevation prompts shown in the issue. Done should be a confirmed diagnosis and a maintainer-approved resolution for elevated WinGet use.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
cli, operating-systems
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.