LocalSystem Service Vulnerability in Duplicati Backup Software
CVE-2026-16157

7.8HIGH

Key Information:

Vendor

Duplicati

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-16157?

The Duplicati backup software version 2.3.0.1 poses a security risk by providing authenticated users with MODIFY permissions that extend to all subdirectories. This can become critical when the software is installed outside of the Program Files directory, leading to the creation of a LocalSystem service that runs from a user-writable directory. Consequently, a standard local user can overwrite any DLL within this service directory. Upon service restart, the operating system loads the altered DLL first, allowing arbitrary code to run with SYSTEM privileges before any managed code executes. This vulnerability can lead to unauthorized actions and severe security breaches.

Affected Version(s)

Duplicati 2.3.0.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.