PatchSiren cyber security CVE debrief
CVE-2026-16157 Duplicati CVE debrief
Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. Installing the software outside of the Program Files directory, or on a custom path, creates a LocalSystem service running from a directory that any standard local user can write to. A standard local user can overwrite any DLL in the service directory. On service restart, the OS loads the attacker's DLL before any managed code runs, executing arbitrary code as SYSTEM. This vulnerability highlights the importance of secure software installation practices and monitoring for potential exploitation.
- Vendor
- Duplicati
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-22
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-22
- Advisory updated
- 2026-07-27
Who should care
System administrators and users of Duplicati v2.3.0.1 backup software should be aware of this vulnerability and take necessary precautions to prevent exploitation. This includes reviewing system configurations, ensuring software is updated or patched, and monitoring for suspicious activity related to the Duplicati service.
Technical summary
The Duplicati v2.3.0.1 backup software has a vulnerability that allows Authenticated Users to have MODIFY permissions that propagate to all subdirectories. This can be exploited by a standard local user to overwrite any DLL in the service directory, leading to arbitrary code execution as SYSTEM. The vulnerability arises from the software's installation outside of the Program Files directory or on a custom path, creating a LocalSystem service running from a directory that any standard local user can write to.
Defensive priority
High
Recommended defensive actions
- Apply the vendor patch or update to a fixed version
- Restrict access to the Duplicati service directory
- Monitor for suspicious activity and DLL changes
- Implement compensating controls, such as DLL whitelisting
- Review system configurations for potential exposure
- Track exceptions and retest remediated assets
Evidence notes
The CVE record was published on 2026-07-22T18:16:55.410Z and has not been modified since then. The NVD entry is currently Deferred. Evidence is limited to public sources and may not reflect the full scope or impact of this vulnerability. Defenders should verify affected systems and review vendor guidance for specific deployment contexts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-16157 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-16157
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-16157 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16157
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://kb.cert.org/vuls/id/847406
-
Source reference
Unverified legacy reference
URL: https://www.kb.cert.org/vuls/id/847406
af854a3a-2127-422b-91ae-364da2661108
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.