PT-2026-63440 · Duplicati · Duplicati

CVE-2026-16157

·

Published

2026-07-22

·

Updated

2026-07-22

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Duplicati version 2.3.0.1
Description Incorrect permission assignments allow authenticated users to have MODIFY permissions that propagate to all subdirectories. When the software is installed outside the default Program Files directory or on a custom path, it creates a LocalSystem service running from a directory that any standard local user can write to. This allows a local attacker to overwrite any DLL in the service directory, leading to arbitrary code execution as SYSTEM upon service restart.
Recommendations Update Duplicati version 2.3.0.1 to the latest patched version. Ensure the software is installed in the default C:Program Files directory.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-16157

Affected Products

Duplicati