Link following in Cleaner One Pro for Windows - CVE-2026-62660
Published: July 17, 2026
Vulnerability details
The vulnerability allows a local user to delete arbitrary files.
The vulnerability exists due to link following in the cleanup process when processing crafted filesystem links during cleanup operations. A local user can trick the cleanup process into deleting a file it should not have access to to delete arbitrary files.
User interaction is required to trigger the cleanup process.