What is CVE-2026-12410?
CVE-2026-12410 is a link following vulnerability in the Uninstaller component of CCleaner prior to version 7.10.1464 on Windows. It allows a local, low-privileged attacker to escalate privileges to SYSTEM by exploiting a symlink or junction created during application uninstallation, which CCleaner follows when deleting application data.
Azərbaycanca: CVE-2026-12410, CCleaner-in 7.10.1464-dən əvvəlki versiyalarında Uninstaller komponentində aşkarlanmış 'link following' zəifliyidir. Bu zəiflik Windows sistemlərində yerli və aşağı səlahiyyətli attacker-ə, proqram silinərkən yaradılmış symlink/junction izlənərək SYSTEM səlahiyyətləri əldə etməyə imkan verir. İstifadəçilər dərhal 7.10.1464 və ya daha yeni versiyaya yeniləməlidir.
FAQ2
In which CCleaner component was the CVE-2026-12410 vulnerability found?
In the Uninstaller component.
What privilege level can an attacker gain by exploiting CVE-2026-12410?
SYSTEM privileges.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.