PT-2026-95411 · Sublime Hq · Sublime Text 4+1

·

CVE-2026-7006

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sublime Text 4 versions prior to Build 4193 Sublime Text 3 versions prior to Build 3208
Description A local privilege escalation issue exists in the update staging mechanism. An unprivileged local attacker can place a malicious DLL in the user-writable staging directory located under %LOCALAPPDATA%. By marking the file as read-only to prevent cleanup, the attacker can trick the elevated installer into copying the DLL into the protected installation directory. This results in the execution of arbitrary code with elevated privileges when a higher-privileged user launches the application.
Recommendations Update Sublime Text 4 to Build 4193 or later. Update Sublime Text 3 to Build 3208 or later.

Exploit

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7006

Affected Products

Sublime Text 3
Sublime Text 4