PT-2026-63440 · Duplicati · Duplicati

CVE-2026-16157

·

Published

2026-07-22

·

Updated

2026-07-27

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Duplicati version 2.3.0.1
Description Incorrect permission assignments allow authenticated users to have MODIFY permissions that propagate to all subdirectories. When the software is installed outside the default Program Files directory or on a custom path, it creates a LocalSystem service running from a directory that any standard local user can write to. This allows a local attacker to overwrite any DLL in the service directory, leading to arbitrary code execution as SYSTEM upon service restart.
Recommendations Update Duplicati version 2.3.0.1 to the latest patched version. Ensure the software is installed in the default C:Program Files directory.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16157

Affected Products

Duplicati