
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-6851 is an improper link resolution before file access ('link following') vulnerability in the File Shredder module of Bitdefender Total Security and Internet Security on Windows. It allows a less-privileged local user to escalate privileges by exploiting a race condition via symbolic links. The vulnerability affects Bitdefender Total Security and Internet Security versions before 27.0.58.315. It was published on July 14, 2026, and carries a CVSS v4.0 base score of 7.0 (High) (GitHub Advisory, Bitdefender Advisory).
The root cause is classified as CWE-59 (Improper Link Resolution Before File Access / 'Link Following'). The File Shredder module, which runs with elevated privileges, does not adequately validate file paths before accessing them, allowing an attacker to substitute a legitimate file path with a symbolic link during a race condition window. A local user with standard (low) privileges can create a symbolic link pointing to a sensitive or privileged resource, and if the timing aligns with the File Shredder's file access operation, the module will follow the link and operate on the attacker-controlled target with elevated rights. This attack pattern corresponds to CAPEC-132 (Symlink Attack) (GitHub Advisory, Bitdefender Advisory).
Successful exploitation allows a local, less-privileged user to escalate to higher privileges on the affected Windows system, with high impact to confidentiality, integrity, and availability of the vulnerable system. An attacker could leverage elevated access to read sensitive files, modify system data, or disrupt system availability. The vulnerability is limited to local exploitation and does not affect subsequent (downstream) systems directly, but elevated privileges could facilitate further lateral movement or persistence within the compromised host (GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.121% (2nd percentile), indicating a low probability of exploitation in the near term. Exploitation requires local access and the ability to win a race condition, which adds practical complexity despite the low attack complexity rating.
mklink or the CreateSymbolicLink API) pointing to a privileged resource (e.g., a system file or directory)..lnk or NTFS junction/symlink entries) created in directories monitored or accessed by the Bitdefender File Shredder module; unusual file deletions or modifications in privileged system directories following a shredding operation.bdservicehost.exe, bdagent.exe) accessing files or directories outside their expected operational scope, particularly system-protected paths.Bitdefender has released a patch in version 27.0.58.315 for both Total Security and Internet Security; users should update to this version or later immediately (Bitdefender Advisory). As a workaround, administrators should restrict local user access and limit the ability of standard users to create symbolic links (controlled via the Windows SeCreateSymbolicLinkPrivilege privilege, which can be managed through Group Policy). Monitoring for suspicious symbolic link creation in directories accessed by the File Shredder module is also recommended as a detection measure.
The Zero Day Initiative published an advisory (ZDI-26-448) referencing this vulnerability, indicating it was likely reported through their coordinated disclosure program (ZDI Advisory). Community coverage has been limited to automated vulnerability tracking platforms and aggregators, with no significant researcher commentary or media coverage identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."