Description
Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege escalation vulnerability that allows unprivileged local attackers to execute arbitrary code with elevated privileges by abusing the update staging mechanism. Attackers can place a malicious DLL in the user-writable staging directory under %LOCALAPPDATA%, mark it read-only to bypass cleanup, and have the elevated installer copy it into the protected installation directory, causing the DLL to execute in the context of any higher-privileged user who subsequently launches the application.
Published: 2026-09-18
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

A local privilege escalation flaw exists in Sublime Text for Windows up to Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3). Unprivileged users can place a malicious DLL in the user‑writable staging directory under %LOCALAPPDATA%, mark it read‑only to prevent cleanup, and then trigger the elevated installer which copies the DLL into the protected installation folder. As the application launches, the DLL executes with the privileges of the higher‑privileged user, allowing arbitrary code execution. This gives an attacker control over the target system while remaining on the local machine.

Affected Systems

Sublime HQ Pty Ltd’s Sublime Text 3 and Sublime Text 4, specifically builds 3207 and 4192. Users running these versions are susceptible unless they have updated past these builds.

Risk and Exploitability

The CVSS score of 7 indicates significant risk. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known mass exploitation yet. The attack requires local access and the ability to place files in the staging directory, but does not require additional privileges to initiate. Once the malicious DLL is copied, the code executes under elevated rights, making the vulnerability highly damaging to confidentiality, integrity, and availability of the affected machine.

Generated by OpenCVE AI on September 19, 2026 at 17:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the latest version of Sublime Text 3 or 4 that removes the vulnerable staging mechanism.
  • Disable automatic updates or configure the update process to require manual approval before installation of staged components.
  • Restrict write permissions on the %LOCALAPPDATA%\Sublime Text\Staging directory, or delete it promptly after updates to prevent malicious DLL placement.

Generated by OpenCVE AI on September 19, 2026 at 17:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:sublimetext:sublime_text_3:3207:*:*:*:*:*:*:*

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Sublimetext
Sublimetext sublime Text 3
Sublimetext sublime Text 4
Vendors & Products Sublimetext
Sublimetext sublime Text 3
Sublimetext sublime Text 4

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege escalation vulnerability that allows unprivileged local attackers to execute arbitrary code with elevated privileges by abusing the update staging mechanism. Attackers can place a malicious DLL in the user-writable staging directory under %LOCALAPPDATA%, mark it read-only to bypass cleanup, and have the elevated installer copy it into the protected installation directory, causing the DLL to execute in the context of any higher-privileged user who subsequently launches the application.
Title Sublime Text 4192/3207 Local Privilege Escalation via Update Staging Mechanism
Weaknesses CWE-494
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Sublimetext Sublime Text 3 Sublime Text 4
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T19:19:26.569Z

Reserved: 2026-04-24T21:16:10.567Z

Link: CVE-2026-7006

cve-icon Vulnrichment

Updated: 2026-09-18T17:00:04.321Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:09.940

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-7006

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-494

    Download of Code Without Integrity Check