CVE-2026-35603: Cursor Still Trusts a World-Writable Folder Cymulate Research Lab disclosed CVE-2026-35603, a privilege escalation vulnerability in AI coding tools including Claude Code, Cursor, Codex CLI, and Gemini CLI. The flaw allows any standard user to plant malicious configuration files in the world-writable C:\ProgramData directory, leading to arbitrary command execution when an administrator launches the tool. Three of the four vendors had not fixed the issue at publication time. C:\ProgramData\ , a folder any standard user can write to.Almost everything I write here is about the insecure code AI editors generate. This one is different. The vulnerability is in the editor itself. Cymulate Research Lab published it on August 11, 2026, as part three of a series on AI tooling security. I read it twice because the first pass felt too simple to be real. It is real, and it is not clever. It is ordinary Windows privilege escalation wearing a new logo. Here is the part that should make you check your machine today: three of the four vendors had not fixed it at publication. The flaw is that these tools read machine-wide settings from C:\ProgramData\