๐Ÿ” CVE Alert

CVE-2016-20086

HIGH 7.8

Vembu StoreGrid 4.0 Unquoted Service Path Privilege Escalation

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

Vembu StoreGrid 4.0 contains an unquoted service path vulnerability in the RemoteBackup and RemoteBackup_webServer services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted path and restart the service to execute code with LocalSystem privileges.

CWE CWE-428
Vendor vembu
Product vembu storegrid
Published Jun 19, 2026
Stay Ahead of the Next One

Get instant alerts for vembu vembu storegrid

Be the first to know when new high vulnerabilities affecting vembu vembu storegrid are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Vembu / Vembu StoreGrid
4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
exploit-db.com: https://www.exploit-db.com/exploits/40582 vulncheck.com: https://www.vulncheck.com/advisories/vembu-storegrid-unquoted-service-path-privilege-escalation

Credits

Joey Lane