AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-12410

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Uninstaller component in CCleaner versions prior to 7.10.1464 on Windows is vulnerable to a symlink/junction attack, enabling local low-privileged users to escalate their privileges to SYSTEM during the uninstallation process. This could allow attackers to manipulate or delete sensitive data with elevated permissions. Organizations using affected versions of CCleaner should prioritize patching this vulnerability to mitigate potential exploitation risks.

CVE
CVE-2026-12410
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Windows

Original NVD Description

Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escalate privileges to SYSTEM via a symlink/junction created during application uninstallation, which CCleaner follows when deleting the application's data folder with elevated integrity.