CVE-2026-6851: Improper link resolution before file access in Bitdefender Total Security via Link Following (VA-13681)
An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and Internet Security on Windows allows a less-privileged local user to elevate rights by leveraging a race conditions via Symbolic Links.
This issue affects Total Security: before 27.0.58.315; Internet Security: before 27.0.58.315.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6851?
The severity of CVE-2026-6851 is rated high with a score of 7.
What vulnerability does CVE-2026-6851 describe?
CVE-2026-6851 describes an improper link resolution before file access vulnerability in the File Shredder module of Bitdefender Total Security.
How can users mitigate CVE-2026-6851?
Users can mitigate CVE-2026-6851 by ensuring they are running the latest version of Bitdefender Total Security and applying any available updates.
Who is affected by CVE-2026-6851?
CVE-2026-6851 affects less-privileged local users of Bitdefender Total Security and Internet Security on Windows systems.
What is the impact of CVE-2026-6851?
The impact of CVE-2026-6851 allows a less-privileged local user to potentially elevate their rights through a race condition exploit using symbolic links.