CVE-2026-6851

HIGH

Improper link resolution before file access in Bitdefender Total Security via Link Following (VA-13681)

Title source: cna
STIX 2.1

Description

An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and Internet Security on Windows allows a less-privileged local user to elevate rights by leveraging a race conditions via Symbolic Links. This issue affects Total Security: before 27.0.58.315; Internet Security: before 27.0.58.315.

Scores

CVSS v4 7.0
EPSS 0.0012
EPSS Percentile 2.3%
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-59
Status published
Products (2)
Bitdefender/Internet Security < 27.0.58.315
Bitdefender/Total Security < 27.0.58.315
Published Jul 14, 2026
Tracked Since Jul 14, 2026