SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-76159

HIGH · CVSS 7 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in the configuration loader of Duplicati for Windows versions prior to 2.4.0.0 allows local low-privileged attackers to escalate their privileges to NT AUTHORITY\SYSTEM by manipulating a preload.json file. This high-severity flaw poses a significant risk to systems running affected versions, making it critical for organizations using Duplicati to prioritize upgrading to the latest version to mitigate potential exploitation.

CVE
CVE-2026-76159
Severity
HIGH
CVSS
7
EPSS
0.10%
Windows

Original NVD Description

Incorrect Permission Assignment for Critical Resource in the configuration loader of Duplicati for Windows versions before v2.4.0.0 allows a local low-privileged attacker to escalate privileges to NT AUTHORITY\SYSTEM via an attacker-controlled preload.json file.