LocalSystem Service Vulnerability in Duplicati Backup Software
CVE-2026-16157
Currently unrated
What is CVE-2026-16157?
The Duplicati backup software version 2.3.0.1 poses a security risk by providing authenticated users with MODIFY permissions that extend to all subdirectories. This can become critical when the software is installed outside of the Program Files directory, leading to the creation of a LocalSystem service that runs from a user-writable directory. Consequently, a standard local user can overwrite any DLL within this service directory. Upon service restart, the operating system loads the altered DLL first, allowing arbitrary code to run with SYSTEM privileges before any managed code executes. This vulnerability can lead to unauthorized actions and severe security breaches.
Affected Version(s)
Duplicati 2.3.0.1
