CVE-2026-76159
Duplicati for Windows - Incorrect Permission Assignment for Critical Resource
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Incorrect Permission Assignment for Critical Resource in the configuration loader of Duplicati for Windows versions before v2.4.0.0 allows a local low-privileged attacker to escalate privileges to NT AUTHORITY\SYSTEM via an attacker-controlled preload.json file.
| CWE | CWE-732 |
| Vendor | duplicati |
| Product | duplicati |
| Published | Sep 15, 2026 |
| Last Updated | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for duplicati duplicati
Be the first to know when new unknown vulnerabilities affecting duplicati duplicati are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Duplicati / Duplicati
0 < v2.4.0.0