CVE-2026-76159
moderateLocal Privilege Escalation to SYSTEM via preload. in Duplicati for Windows
Duplicati for Windows versions before v2.4.0.0 suffer from an incorrect permission assignment (CWE-732) on a critical resource used by its configuration loader, which runs in the context of the highly privileged Duplicati service. A local attacker with only low-privileged access can plant an attacker-controlled preload. file that the loader picks up, causing attacker-supplied configuration (and effectively code execution) to run as NT AUTHORITY\SYSTEM. Exploitation requires prior local access and some user interaction, but yields full system-level compromise of the affected machine. Anyone running Duplicati on Windows prior to v2.4.0.0 is affected, with the greatest risk on multi-user systems where untrusted local accounts exist. No public proof of concept is known, the flaw is not in CISA's KEV catalog, and there is no evidence of in-the-wild exploitation at this time.
What to do: Upgrade Duplicati for Windows to v2.4.0.0 or later as soon as possible. In the interim, tighten NTFS permissions on the Duplicati configuration directory so low-privileged users cannot write preload., and audit existing installs for unexpected or recently modified preload. files. Restrict local account creation on hosts running the Duplicati service, since the flaw requires local low-privileged access to exploit.
| Duplicati for Windows | before v2.4.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect Permission Assignment for Critical Resource in the configuration loader of Duplicati for Windows versions before v2.4.0.0 allows a local low-privileged attacker to escalate privileges to NT AUTHORITY\SYSTEM via an attacker-controlled preload.json file.
- Weakness
- CWE-732
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.