PT-2026-67676 · Asustor · Backup Plan+1

CVE-2026-18759

·

Published

2026-08-04

·

Updated

2026-08-04

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ASUSTOR Backup Plan versions prior to 2.0.7.10172 ASUSTOR EZSync versions prior to 1.1.1.3114
Description The background service runs as NT AUTHORITYSYSTEM and uses a file-based inter-process communication (IPC) mechanism protected by AES encryption. Since the encryption key file is readable by standard users and protected by DPAPI (Data Protection API), an authenticated local user can recover the key to forge valid IPC requests. Additionally, the service fails to verify the identity of the requesting process and employs an insufficient substring check for destination paths. This allows a local attacker to send crafted encrypted requests using directory traversal sequences to perform arbitrary file reads and writes with NT AUTHORITYSYSTEM privileges, resulting in full local privilege escalation.
Recommendations Update ASUSTOR Backup Plan to a version later than 2.0.7.10171. Update ASUSTOR EZSync to a version later than 1.1.1.3113.

Fix

LPE

Improper Privilege Management

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18759

Affected Products

Backup Plan
Ezsync