CVE-2026-44470
Last modified
CVE-2026-44470 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. Prior to 1.3834.0, the CoworkVMService component in Claude Desktop for Windows ran as SYSTEM and did not validate whether the VM bundle directory was a real directory or an NTFS directory junction before creating files within it. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. Prior to 1.3834.0, the CoworkVMService component in Claude Desktop for Windows ran as SYSTEM and did not validate whether the VM bundle directory was a real directory or an NTFS directory junction before creating files within it. A local non-elevated user could replace the user-writable VM bundle directory with a directory junction pointing to an attacker-chosen location, causing the service to create a SYSTEM-owned file in an arbitrary directory. This could be leveraged for local privilege escalation. This vulnerability is fixed in 1.3834.0.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Anthropic | Claude Desktop | < 1.3834.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-44470?
How severe is CVE-2026-44470?
How do I fix CVE-2026-44470?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-44465Zed is a code editor. Prior to 0.227.1, Zed IDE executes arb…8.6
- CVE-2026-44466Zed is a code editor. Prior to 0.229.0, Zed's terminal tool …8.6
- CVE-2026-44467The Claude Desktop app gives you Claude Code with a graphica…6.8
- CVE-2026-44468The affected product creates a directory with insecure defau…8.5
- CVE-2026-44469The affected product extracts installation files to a tempor…7
- CVE-2026-4447Inappropriate implementation in V8 in Google Chrome prior to…8.8
- CVE-2026-44471gitoxide is an implementation of git written in Rust. Prior …7.8
- CVE-2026-44473Ella Core is a 5G core designed for private networks. Prior …7.1
- CVE-2026-44474Ella Core is a 5G core designed for private networks. Prior …3.7
- CVE-2026-44475Ella Core is a 5G core designed for private networks. Prior …6.1
- CVE-2026-44477CloudNativePG is a platform designed to manage PostgreSQL da…9.9
- CVE-2026-44478hoppscotch is an open source API development ecosystem. The …7.5
Are you affected by CVE-2026-44470?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
