CVE-2026-76159
Received Received - Intake

Incorrect Permission Assignment in Duplicati for Windows

Vulnerability report for CVE-2026-76159, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: ZUSO Advanced Research Team (ZUSO ART)

Description

Incorrect Permission Assignment for Critical Resource in the configuration loader of Duplicati for Windows versions before v2.4.0.0 allows a local low-privileged attacker to escalate privileges to NT AUTHORITY\SYSTEM via an attacker-controlled preload.json file.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
duplicati duplicati to 2.4.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves incorrect permission assignment in the configuration loader of Duplicati for Windows versions before v2.4.0.0. A local low-privileged attacker can exploit this by placing a malicious preload.json file to escalate privileges to NT AUTHORITY\SYSTEM.

Impact Analysis

An attacker with low privileges could gain full system control, allowing them to execute arbitrary code, access sensitive data, or install malware. This could lead to complete system compromise on affected Windows systems running vulnerable Duplicati versions.

Mitigation Strategies

Update Duplicati for Windows to version v2.4.0.0 or later to address the incorrect permission assignment issue. Remove any untrusted preload.json files that may exist in the configuration directory.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76159. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart