Junglewise Threat Intelligence

CVE-2026-6851: Bitdefender Total Security privilege escalation in File Shredder

CVE-2026-6851 · Severity: info · CVSS 7 · Published 2026-07-14

Technologies: Bitdefender Internet Security, Bitdefender Total Security. Vendors: Bitdefender.

Executive brief

A security flaw exists in the File Shredder tool within Bitdefender's Windows security suites, which is designed to permanently delete sensitive files. An attacker who already has limited access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to bypass security protections, access private data, or disrupt operations.

Technical details

An improper link resolution (CWE-59) vulnerability exists in the File Shredder module of Bitdefender Total Security and Internet Security for Windows. The flaw stems from a race condition during file access where the application fails to properly validate a file path before performing shredding operations. A local, low-privileged attacker can exploit this by creating symbolic links to sensitive system files. If a user with higher privileges interacts with the shredder, the attacker can leverage the race condition to gain elevated rights. The issue is resolved in version 27.0.58.315.

Affected products

  • Bitdefender Total Security before 27.0.58.315
  • Bitdefender Internet Security before 27.0.58.315

Timeline

  • 2026-07-14: advisory
  • 2026-07-14: disclosed

References

Related threats