Description
Incorrect Permission Assignment for Critical Resource in the configuration loader of Duplicati for Windows versions before v2.4.0.0 allows a local low-privileged attacker to escalate privileges to NT AUTHORITY\SYSTEM via an attacker-controlled preload.json file.
Published: 2026-09-15
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in the configuration loader of Duplicati for Windows, which incorrectly assigns permissions to a critical resource. An attacker who has local low‑privileged access can place an attacker‑controlled preload.json file in the designated location. By doing so, the application will grant the file’s contents execution with elevated privileges, effectively allowing the attacker to gain SYSTEM level rights on the host. This raises the integrity and confidentiality of the system, as the attacker can modify or read any data and potentially compromise other services running on the machine.

Affected Systems

Duplicati for Windows versions earlier than 2.4.0.0 are affected. The vulnerability impacts the Duplicati application in its Windows build, and it requires the victim machine to be running a vulnerable version of this product. No other Duplicati products or versions are listed as affected.

Risk and Exploitability

The CVSS score of 7 indicates high severity, but the EPSS score of less than 1% shows that the likelihood of exploitation is low at present. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, suggesting no known active exploitation. However, the attack vector is local, meaning an attacker must already have some level of local user access. If an attacker can create a preload.json file, privilege escalation to SYSTEM should be possible. The primary risk is the potential for an attacker to tamper with system configurations, install persistence mechanisms, or exfiltrate data once the SYSTEM privilege is achieved.

Generated by OpenCVE AI on September 17, 2026 at 18:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Duplicati to version 2.4.0.0 or later, which removes the privilege‑assignment flaw in the configuration loader.
  • Ensure that any directories used by Duplicati for configuration files have permissions that prevent local users from creating or overwriting preload.json files.
  • Apply the principle of least privilege to local user accounts on the system so that they cannot write to the Duplicati configuration directory, and monitor for any unauthorized file creation attempts.

Generated by OpenCVE AI on September 17, 2026 at 18:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://zuso.ai/advisory/ cve-icon cve-icon
History

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Duplicati
Duplicati duplicati
Vendors & Products Duplicati
Duplicati duplicati

Tue, 15 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description Incorrect Permission Assignment for Critical Resource in the configuration loader of Duplicati for Windows versions before v2.4.0.0 allows a local low-privileged attacker to escalate privileges to NT AUTHORITY\SYSTEM via an attacker-controlled preload.json file.
Title Duplicati for Windows - Incorrect Permission Assignment for Critical Resource
Weaknesses CWE-732
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Duplicati Duplicati
cve-icon MITRE

Status: PUBLISHED

Assigner: ZUSO ART

Published:

Updated: 2026-09-15T13:33:17.592Z

Reserved: 2026-08-19T08:03:53.871Z

Link: CVE-2026-76159

cve-icon Vulnrichment

Updated: 2026-09-15T13:33:12.589Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T09:16:43.900

Modified: 2026-09-16T13:42:48.440

Link: CVE-2026-76159

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource