Back to all
2026-09-15

Duplicati for Windows - Incorrect Permission Assignment for Critical Resource

ZUSOART ID
ZA-2026-08
CVE ID
CVE-2026-76159
Vulnerability Type
CWE-732: Incorrect Permission Assignment for Critical Resource
CVSS 4.0 Base
7
Description

Incorrect  Permission Assignment for Critical Resource in the  configuration loader of Duplicati for  Windows versions before v2.4.0.0 allows a local low-privileged attacker to  escalate privileges to NT AUTHORITY\SYSTEM via an attacker-controlled  preload.json file.

Vendor
Duplicati
Product
Category
Version affected
Duplicati for Windows
Before v2.4.0.0
Mitigations

Update to  Duplicati for Windows v2.4.0.0

Release date
2026-09-15
Credit

Ping Yu Chen (Fox) of ZUSO ART