CVE-2026-76159: Duplicati for Windows - Incorrect Permission Assignment for Critical Resource
Incorrect Permission Assignment for Critical Resource in the configuration loader of Duplicati for Windows versions before v2.4.0.0 allows a local low-privileged attacker to escalate privileges to NT AUTHORITY\SYSTEM via an attacker-controlled preload.json file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Duplicati for Windowsto a version that resolves this vulnerability.Fixed in v2.4.0.0
Event History
Frequently Asked Questions
Who can exploit this issue?
A local attacker with low privileges on a Windows system running an affected Duplicati version can exploit it. Remote access alone is not described as sufficient.
What does an attacker need to control?
The attacker needs to supply or control a preload.json file used by the configuration loader. The issue is caused by incorrect permissions on that critical resource.
What is the impact of successful exploitation?
Successful exploitation allows privilege escalation to NT AUTHORITY\SYSTEM.
Which versions should be remediated?
Duplicati for Windows versions before 2.4.0.0 are affected. Upgrade to version 2.4.0.0 or later.