CVE-2026-7006 PUBLISHED

Sublime Text 4192/3207 Local Privilege Escalation via Update Staging Mechanism

Assigner: VulnCheck
Reserved: 24.04.2026 Published: 18.09.2026 Updated: 18.09.2026

Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege escalation vulnerability that allows unprivileged local attackers to execute arbitrary code with elevated privileges by abusing the update staging mechanism. Attackers can place a malicious DLL in the user-writable staging directory under %LOCALAPPDATA%, mark it read-only to bypass cleanup, and have the elevated installer copy it into the protected installation directory, causing the DLL to execute in the context of any higher-privileged user who subsequently launches the application.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7

Product Status

Vendor Sublime HQ Pty Ltd
Product Sublime Text 4
Versions Default: unaffected
  • Version 4192 is affected
Vendor Sublime HQ Pty Ltd
Product Sublime Text 3
Versions Default: unaffected
  • Version 3207 is affected

Credits

  • Kyle Anthony finder

References

Problem Types

  • Download of Code Without Integrity Check CWE