Description
G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the Backup Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-28665.
Published: 2026-07-29
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker can create a symbolic link that the G DATA Total Security Backup Service follows, allowing the deletion of arbitrary files. By abusing the service in this way, the attacker can elevate privileges from a low‑privileged user to SYSTEM and execute arbitrary code with full system rights. The weakness is a path‑traversal or symbolic‑link handling flaw (CWE‑59).

Affected Systems

The vulnerability affects installations of G DATA Total Security. No specific version information is provided, so all current installations are potentially impacted.

Risk and Exploitability

The CVSS score of 7.8 indicates a high‑severity flaw, yet the EPSS score of less than 1% suggests that exploitation is unlikely at present. It is not listed in the CISA KEV catalog. Exploitation requires local access and the ability to run low‑privileged code to create the malicious symbolic link; after that, the backup service deletes the target file and the attacker can trigger privilege escalation to SYSTEM.

Generated by OpenCVE AI on August 3, 2026 at 12:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s latest patch or upgrade G DATA Total Security to a version that corrects the backup service link handling flaw.
  • If a patch is not yet available, disable the G DATA Total Security Backup Service or restrict local user access to the backup component to prevent link creation.
  • Ensure that directories used by the backup service are read‑only for non‑trusted users and that symbolic link creation is not permitted in those paths.
  • Periodic review of local accounts for excess privileges and monitoring for unexpected file deletions.

Generated by OpenCVE AI on August 3, 2026 at 12:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Gdata-software
Gdata-software total Security
Vendors & Products Gdata-software
Gdata-software total Security

Wed, 29 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Description G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Backup Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-28665.
Title G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability
Weaknesses CWE-59
References
Metrics cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Gdata-software Total Security
cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2026-07-30T13:41:40.892Z

Reserved: 2026-06-24T21:22:42.496Z

Link: CVE-2026-13268

cve-icon Vulnrichment

Updated: 2026-07-30T13:41:04.868Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-29T20:17:00.700

Modified: 2026-07-30T14:19:24.857

Link: CVE-2026-13268

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T13:00:07Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')