CVE-2026-26225: Intego Personal Backup Task File Privilege Escalation
Intego Personal Backup, a macOS backup utility that allows users to create scheduled backups and bootable system clones, contains a local privilege escalation vulnerability. Backup task definitions are stored in a location writable by non-privileged users while being processed with elevated privileges. By crafting a malicious serialized task file, a local attacker can trigger arbitrary file writes to sensitive system locations, leading to privilege escalation to root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26225?
CVE-2026-26225 is classified as a local privilege escalation vulnerability.
How do I fix CVE-2026-26225?
To fix CVE-2026-26225, ensure that the backup task definitions are stored in a secure location with appropriate write permissions.
What systems are affected by CVE-2026-26225?
CVE-2026-26225 affects Intego Personal Backup on macOS systems.
What type of vulnerability is CVE-2026-26225?
CVE-2026-26225 is a privilege escalation vulnerability that allows unauthorized users to gain elevated access.
Can CVE-2026-26225 be exploited remotely?
CVE-2026-26225 requires local access to exploit, meaning it cannot be exploited remotely.