CVE-2026-55567: BleachBit: Exploit File Delete to Escalate Privilege
BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not lock and validate a target's parent directory before deletion. A local unprivileged user can replace that directory with a Windows junction and use a native symlink to redirect the elevated deletion to an attacker-selected file. The arbitrary privileged file deletion can be combined with Windows Installer behavior to obtain local SYSTEM privileges. This issue is fixed in version 6.0.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BleachBitto a version that resolves this vulnerability.Fixed in 6.0.1
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Windows systems running BleachBit versions earlier than 6.0.1 are exposed when privileged cleaning is used. Exploitation requires a local unprivileged user on the affected system.
What does an attacker need to exploit the vulnerability?
The attacker needs local unprivileged access and must be able to replace the target's parent directory with a Windows junction and use a native symlink. The attack redirects an elevated deletion operation to an attacker-selected file.
What is the potential impact of successful exploitation?
An attacker can cause arbitrary file deletion with elevated privileges. The vulnerability can be combined with Windows Installer behavior to obtain local SYSTEM privileges.
How can the issue be remediated?
Upgrade BleachBit to version 6.0.1, which fixes the parent-directory locking and validation issue during privileged Windows cleaning.