LocalSystem Service Vulnerability in Duplicati Backup Software
CVE-2026-16157

Currently unrated

Key Information:

Vendor

Duplicati

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-16157?

The Duplicati backup software version 2.3.0.1 poses a security risk by providing authenticated users with MODIFY permissions that extend to all subdirectories. This can become critical when the software is installed outside of the Program Files directory, leading to the creation of a LocalSystem service that runs from a user-writable directory. Consequently, a standard local user can overwrite any DLL within this service directory. Upon service restart, the operating system loads the altered DLL first, allowing arbitrary code to run with SYSTEM privileges before any managed code executes. This vulnerability can lead to unauthorized actions and severe security breaches.

Affected Version(s)

Duplicati 2.3.0.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.