CVE-2026-55567
7.8 HIGHpublic exploit availablePublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw allows a local unprivileged user to replace a target directory with a Windows junction and symlink, enabling arbitrary privileged file deletion which can lead to SYSTEM privileges.
- Exploitability
- Exploitation requires preconditions such as access to a vulnerable BleachBit version and the ability to manipulate directory structures; moderately hard.
- Blast radius
- If exploited, it could result in full system compromise for the affected machine.
- Prioritized remediation
- Update BleachBit to version 6.0.1 or later immediately.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not lock and validate a target's parent directory before deletion. A local unprivileged user can replace that directory with a Windows junction and use a native symlink to redirect the elevated deletion to an attacker-selected file. The arbitrary privileged file deletion can be combined with Windows Installer behavior to obtain local SYSTEM privileges. This issue is fixed in version 6.0.1.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-367
Public exploit & PoC references
- https://github.com/bleachbit/bleachbit/commit/ee128238e92c7192f0c4d6406b1bd0cd9155e7e0
- https://github.com/bleachbit/bleachbit/pull/1774
- https://github.com/bleachbit/bleachbit/releases/tag/v6.0.1
- https://github.com/bleachbit/bleachbit/security/advisories/GHSA-vcjw-px28-5w94
- https://github.com/bleachbit/bleachbit/security/advisories/GHSA-vcjw-px28-5w94
All references
- https://github.com/bleachbit/bleachbit/commit/ee128238e92c7192f0c4d6406b1bd0cd9155e7e0
- https://github.com/bleachbit/bleachbit/pull/1774
- https://github.com/bleachbit/bleachbit/releases/tag/v6.0.1
- https://github.com/bleachbit/bleachbit/security/advisories/GHSA-vcjw-px28-5w94
- https://github.com/bleachbit/bleachbit/security/advisories/GHSA-vcjw-px28-5w94
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-15979
- MEDIUMCVE-2026-49004
- HIGHCVE-2026-51400PoC
- HIGHCVE-2026-51401PoC
- HIGHCVE-2026-71259PoC
- MEDIUMCVE-2026-82163
- HIGHCVE-2026-94146
- HIGHCVE-2026-94403
Related by shared AI tags and CWE weakness class. Browse the full archive.