Junglewise Threat Intelligence

CVE-2026-7006: Sublime Text local privilege escalation in update staging mechanism

CVE-2026-7006 · Severity: high · CVSS 7.3 · Published 2026-09-18

Executive brief

Sublime Text for Windows contains a privilege escalation vulnerability in its update process that allows a local attacker to execute arbitrary code with elevated privileges. By placing a malicious DLL file in a user-writable staging directory and marking it read-only, an attacker can trick the elevated installer into copying the malicious file to the protected installation directory, where it will be executed by any user (including administrators) who launches the application. This could enable an attacker on a shared system to gain control over other users' sessions and install persistent malware.

Technical details

The vulnerability exists in how Sublime Text handles downloaded updates on Windows: staged files in %LOCALAPPDATA%\Sublime Text\ are copied to C:\Program Files\Sublime Text\ by an elevated installer (via UAC) without verification against the signed update package. The cleanup phase of the updater fails to remove read-only files, allowing an attacker to bypass pre-installation cleanup. The DLL is then copied by the elevated process and loaded by any subsequent Sublime Text launch, executing arbitrary code in that user's context.

Affected products

  • Sublime HQ Pty Ltd Sublime Text 4 through Build 4192
  • Sublime HQ Pty Ltd Sublime Text 3 through Build 3207

Timeline

  • 2026-09-18: disclosed: Vulnerability details published on GitHub Gist and NVD

References