Microsoft has acknowledged a Windows 11 bug that can cause the CapabilityAccessManager.db-wal file under C:\ProgramData\Microsoft\Windows\CapabilityAccessManager\ to grow abnormally, consuming tens or even hundreds of gigabytes of disk space. The file is tied to the Capability Access Manager service, which logs app-permission activity for privacy-sensitive features including the camera, microphone, location, and screen capture. Affected systems may show the lost capacity under System files or System & reserved storage rather than as user data, making the issue difficult to spot until free space drops sharply.
Microsoft said the problem was addressed in the June 23 optional preview update and that the fix will also be rolled out broadly in the July Patch Tuesday release. Users can verify exposure by inspecting the CapabilityAccessManager folder or checking whether the db-wal file has grown unusually large; some reports cited sizes approaching 500GB. As a temporary workaround before the broader fix arrives, users can rename the affected file so Windows regenerates it.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft acknowledged the Windows 11 storage bug in release notes for KB5095093 and said a fix would be included for all users in the July 14, 2026 Patch Tuesday release.
Microsoft addressed a Windows 11 bug that could cause the CapabilityAccessManager.db-wal file to grow abnormally and consume large amounts of disk space in the optional preview update released on June 23, 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
ghacks.net
Open sourcezdnet.com
Open sourcewindowslatest.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.