PT-2026-2399 · Cobian · Cobian Backup

Hejap Zairy

·

Published

2026-01-13

·

Updated

2026-03-02

·

CVE-2022-50923

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cobian Backup version 0.9
Description A local user can execute arbitrary code with elevated system privileges. This is due to an unquoted service path in the CobianReflectorService, allowing attackers to inject malicious code that executes with LocalSystem permissions during service startup.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider modifying the service path to include quotes to prevent malicious code execution.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-50923

Affected Products

Cobian Backup