Link following in Cleaner One Pro for Windows - CVE-2026-62660

 

Link following in Cleaner One Pro for Windows - CVE-2026-62660

Published: July 17, 2026


Vulnerability identifier: #VU138270
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-62660
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to delete arbitrary files.

The vulnerability exists due to link following in the cleanup process when processing crafted filesystem links during cleanup operations. A local user can trick the cleanup process into deleting a file it should not have access to to delete arbitrary files.

User interaction is required to trigger the cleanup process.


Affected software

Cleaner One Pro for Windows

How to mitigate CVE-2026-62660

Install security update from vendor's website.

Cleaner One Pro for Windows - update to 6.8.375

External References

Related Security Bulletins