BitdefenderCVE-2026-6851
Bitdefender Total Security: link following
High7.0CVE-2026-6851 · Published Jul 14, 2026 · updated Aug 12, 2026
An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and Internet Security on Windows allows a less-privileged local user to elevate rights by leveraging a race conditions via Symbolic Links. This issue affects Total Security: before 27.0.58.315; Internet Security: before 27.0.58.315.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Internet Security Product | < 27.0.58.315 | 27.0.58.315 |
| Total Security Product | < 27.0.58.315 | 27.0.58.315 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-59