๐Ÿ” CVE Alert

CVE-2026-55567

HIGH 7.8

BleachBit: Exploit File Delete to Escalate Privilege

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not lock and validate a target's parent directory before deletion. A local unprivileged user can replace that directory with a Windows junction and use a native symlink to redirect the elevated deletion to an attacker-selected file. The arbitrary privileged file deletion can be combined with Windows Installer behavior to obtain local SYSTEM privileges. This issue is fixed in version 6.0.1.

CWE CWE-367
Vendor bleachbit
Product bleachbit
Published Sep 21, 2026
Last Updated Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for bleachbit bleachbit

Be the first to know when new high vulnerabilities affecting bleachbit bleachbit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

bleachbit / bleachbit
< 6.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/bleachbit/bleachbit/security/advisories/GHSA-vcjw-px28-5w94 github.com: https://github.com/bleachbit/bleachbit/pull/1774 github.com: https://github.com/bleachbit/bleachbit/commit/ee128238e92c7192f0c4d6406b1bd0cd9155e7e0 github.com: https://github.com/bleachbit/bleachbit/releases/tag/v6.0.1