HIGH
ASUSTOR Inc.
CVE published 2026-08-04
CVE-2026-18759
The CVE-2026-18759 vulnerability affects the background service of ABP (ASUSTOR Backup Plan) and AES (ASUSTOR EZSync), which run as NT AUTHORITY SYSTEM. These services implement a file-based inter-process communication (IPC) mechanism protected by AES encryption. However, the encryption key file is readable by standard users and protected using DPAPI, allowing authenticated local users to recover the key [truncated]