Vulnerability intelligence
CVE-2026-33694
This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condition potentially facilitates arbitrary code execution, whereby an attacker may exploit the vulnerability to execute malicious code with elevated SYSTEM privileges.
CVSS Score
7.4
High
EPSS — Exploit Probability
0.1%
Riskier than 4% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Apr 24, 2026 · latest Apr 24, 2026
Coverage timeline
-
Critical Path Traversal Flaw Found in CrowdStrike LogScale SIEMwww.securityweek.com · Apr 24, 2026