๐Ÿ” CVE Alert

CVE-2026-7006

HIGH 7.3

Sublime Text 4192/3207 Local Privilege Escalation via Update Staging Mechanism

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th

Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege escalation vulnerability that allows unprivileged local attackers to execute arbitrary code with elevated privileges by abusing the update staging mechanism. Attackers can place a malicious DLL in the user-writable staging directory under %LOCALAPPDATA%, mark it read-only to bypass cleanup, and have the elevated installer copy it into the protected installation directory, causing the DLL to execute in the context of any higher-privileged user who subsequently launches the application.

CWE CWE-494
Vendor sublime hq pty ltd
Product sublime text 4
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for sublime hq pty ltd sublime text 4

Be the first to know when new high vulnerabilities affecting sublime hq pty ltd sublime text 4 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Sublime HQ Pty Ltd / Sublime Text 4
4192
Sublime HQ Pty Ltd / Sublime Text 3
3207

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
gist.github.com: https://gist.github.com/anthok/765b3ca0223fabee38f51d8f832e2175 sublimetext.com: https://www.sublimetext.com/ vulncheck.com: https://www.vulncheck.com/advisories/sublime-text-4192-3207-local-privilege-escalation-via-update-staging-mechanism

Credits

Kyle Anthony