SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13268

HIGH · CVSS 7.8 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The vulnerability in G DATA Total Security allows local attackers to escalate privileges by exploiting a flaw in the Backup Service, specifically through the creation of a symbolic link that enables file deletion. This can lead to arbitrary code execution with SYSTEM-level privileges, significantly compromising system security. Organizations using G DATA Total Security should prioritize addressing this vulnerability to mitigate potential risks from local threats.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-13268
Severity
HIGH
CVSS
7.8
EPSS
0.15%

Original NVD Description

G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Backup Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-28665.