CVE-2026-4824
Improper Privilege Management in Iperius Backup Job Configuration
Publication date: 2026-03-25
Last updated on: 2026-04-29
Assigner: VulDB
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| enter_software | iperius_backup | to 8.7.3 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-266 | A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor. |
| CWE-269 | The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in Enter Software Iperius Backup versions up to 8.7.3, specifically in the Backup Job Configuration File Handler component. It involves improper privilege management, meaning that the system does not correctly handle user permissions related to backup job configurations. The attack must be performed locally and is considered to have high complexity, making exploitation difficult. However, the exploit has been publicly disclosed.
How can this vulnerability impact me? :
If exploited, this vulnerability can lead to unauthorized actions due to improper privilege management. This means an attacker with local access and some level of privileges could potentially escalate their privileges or manipulate backup job configurations in a way that compromises confidentiality, integrity, and availability of data handled by the backup software.
What immediate steps should I take to mitigate this vulnerability?
The immediate step to mitigate this vulnerability is to upgrade Enter Software Iperius Backup to version 8.7.4, which contains the fix for this issue.
Since the attack must be carried out locally and has high complexity, ensuring that only trusted users have local access can also help reduce risk.