Local Privilege Escalation in Claude Desktop App by Anthropic
CVE-2026-44470

8.5HIGH

Key Information:

Vendor

Anthropics

Vendor
CVE Published:
13 May 2026

What is CVE-2026-44470?

The Claude Desktop app prior to version 1.3834.0 contains a vulnerability in the CoworkVMService component, which runs with SYSTEM privileges. It lacks proper validation of the VM bundle directory, allowing a local non-elevated user to craft a directory junction that redirects file creation to an attacker-controlled location. This flaw enables the elevation of privileges, granting unauthorized access to system resources and potentially leading to further exploitation. Users are advised to update to version 1.3834.0 or later to mitigate this risk.

Affected Version(s)

claude-code < 1.3834.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.