PT-2026-33175 · Barracuda · Barracuda Rmm

CVE-2026-22676

·

Published

2026-04-15

·

Updated

2026-04-16

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Barracuda RMM versions prior to 2025.2.2
Description An issue exists where overly permissive filesystem Access Control Lists (ACLs) on the 'C:WindowsAutomation' directory allow local attackers to gain SYSTEM-level privileges. Attackers can modify existing automation content or place controlled files in this directory, which are subsequently executed under the NT AUTHORITYSYSTEM account during routine automation cycles.
Recommendations Update to version 2025.2.2.

Fix

LPE

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-22676

Affected Products

Barracuda Rmm