CVE Explorer
CVE-2026-16157
Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. Installing the software outside of the Program Files directory, or on a custom path, creates a LocalSystem service running from a directory that any standard local user can write to. A standard local user can overwrite any DLL in the service directory. On service restart, the OS loads the attacker's DLL before any managed code runs, executing arbitrary code as SYSTEM.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"description":"CWE-732: Incorrect Permission Assignment for Critical Resource","lang":"en"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1cfcd4e7f90badc990399c908532ae439ca2830d02e0c539005c6c5f30744816 · sha256:5a5572fccc297adc… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-732","description":"CWE-732 Incorrect Permission Assignment for Critical Resource","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1cfcd4e7f90badc990399c908532ae439ca2830d02e0c539005c6c5f30744816 · sha256:5a5572fccc297adc… · /containers/adp/1/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"Duplicati","vendor":"Duplicati","versions":[{"status":"affected","version":"2.3.0.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:1cfcd4e7f90badc990399c908532ae439ca2830d02e0c539005c6c5f30744816 · sha256:5a5572fccc297adc… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:1cfcd4e7f90badc990399c908532ae439ca2830d02e0c539005c6c5f30744816 · sha256:5a5572fccc297adc… · /containers/adp/1/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"description":"CWE-732: Incorrect Permission Assignment for Critical Resource","lang":"en"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1cfcd4e7f90badc990399c908532ae439ca2830d02e0c539005c6c5f30744816 · sha256:5a5572fccc297adc… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-732","description":"CWE-732 Incorrect Permission Assignment for Critical Resource","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1cfcd4e7f90badc990399c908532ae439ca2830d02e0c539005c6c5f30744816 · sha256:5a5572fccc297adc… · /containers/adp/1/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"https://kb.cert.org/vuls/id/847406"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1cfcd4e7f90badc990399c908532ae439ca2830d02e0c539005c6c5f30744816 · sha256:5a5572fccc297adc… · /containers/cna/references/0
{"url":"https://www.kb.cert.org/vuls/id/847406"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1cfcd4e7f90badc990399c908532ae439ca2830d02e0c539005c6c5f30744816 · sha256:5a5572fccc297adc… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.