CVE-2026-76159EPSS p2.3%
CVE-2026-76159CVE-2026-76159
Description
Incorrect Permission Assignment for Critical Resource in the configuration loader of Duplicati for Windows versions before v2.4.0.0 allows a local low-privileged attacker to escalate privileges to NT AUTHORITY\SYSTEM via an attacker-controlled preload.json file.
Scoring
| EPSS | 0.13% probability of exploitation · percentile 2.3% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-16 |