{"document":{"acknowledgments":[{"urls":["https://kb.cert.org/vuls/id/847406#acknowledgements"]}],"category":"CERT/CC Vulnerability Note","csaf_version":"2.0","notes":[{"category":"summary","text":"### Overview\r\nDuplicati v2.3.0.1 is vulnerable to arbitrary code execution when installed outside the default `C:\\Program Files\\Duplicati 2\\` directory. An attacker with local user privileges who can write files to the Duplicati installation directory can execute arbitrary code by placing malicious files, such as DLLs, in that directory. To mitigate this vulnerability, install Duplicati in the default `C:\\Program Files\\` directory or update to the latest fixed version.\r\n\r\n### Description\r\nDuplicati is a free, open-source backup solution that stores data across cloud and local storage platforms. On Windows, Duplicati is distributed as an MSI installer. By default, the installer deploys the application to `C:\\Program Files\\Duplicati 2\\`, where the directory inherits the standard protected ACLs provided by Windows.\r\n\r\nThe following vulnerability affects Duplicati v2.3.0.1:\r\n\r\n***CVE-2026-16157***  During installation, the MSI registers a `LocalSystem` service that executes binaries from the Duplicati installation directory. When the default installation path under `C:\\Program Files\\` is used, the directory is protected by the appropriate ACLs. However, if Duplicati is installed to a non-default location, the installer does not apply equivalent permissions to the installation directory. As a result, standard local users may have write access to files within the installation directory, allowing an attacker to place malicious files, such as DLLs, that may be loaded by the `LocalSystem` service, resulting in arbitrary code execution with elevated privileges.\r\n\r\n### Impact\r\nA local attacker with write access to a non-default Duplicati installation directory can replace or introduce DLLs used by the Duplicati service. Upon service restart, the Windows loader loads the attacker's DLL before any managed code is executed, allowing arbitrary code to run with `NT AUTHORITY\\SYSTEM` privileges.\r\n\r\n### Solution\r\nInstall Duplicati in the default installation directory (`C:\\Program Files\\Duplicati 2\\`). If a non-default installation directory is required, ensure it is manually configured with ACLs that provide equivalent protections to those applied under the `C:\\Program Files\\` directory. Additionally, install all vendor patches and updates that address this vulnerability. See Vendor Information for details\r\n\r\n### Acknowledgements\r\nThank you to Valton Tahiri for discovering and reporting this vulnerability. This document was written by Bob Kemerer.","title":"Summary"},{"category":"legal_disclaimer","text":"THIS DOCUMENT IS PROVIDED ON AN 'AS IS' BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. ","title":"Legal Disclaimer"},{"category":"other","text":"CERT/CC Vulnerability Note is a limited advisory. It primarily identifies vendors impacted by the advisory and not specific products. We only support \"known_affected\" and \"known_not_affected\" status. Please consult the vendor's statements and advisory URL if provided by the vendor for more details ","title":"Limitations of Advisory"}],"publisher":{"category":"coordinator","contact_details":"Email: cert@cert.org, Phone: +1412 268 5800","issuing_authority":"CERT/CC under DHS/CISA https://www.cisa.gov/cybersecurity also see https://kb.cert.org/ ","name":"CERT/CC","namespace":"https://kb.cert.org/"},"references":[{"url":"https://certcc.github.io/certcc_disclosure_policy","summary":"CERT/CC vulnerability disclosure policy"},{"summary":"CERT/CC document released","category":"self","url":"https://kb.cert.org/vuls/id/847406"},{"url":"https://duplicati.com/","summary":"https://duplicati.com/"}],"title":"Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability","tracking":{"current_release_date":"2026-07-22T17:24:02+00:00","generator":{"engine":{"name":"VINCE","version":"3.0.43"}},"id":"VU#847406","initial_release_date":"2026-07-22 17:24:02.422624+00:00","revision_history":[{"date":"2026-07-22T17:24:02+00:00","number":"1.20260722172402.1","summary":"Released on 2026-07-22T17:24:02+00:00"}],"status":"final","version":"1.20260722172402.1"}},"vulnerabilities":[{"title":"Duplicati backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories.","notes":[{"category":"summary","text":"Duplicati backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. Installing the software outside of the Program Files directory, or on a custom path, creates a LocalSystem service running from a directory that any standard local user can write to. A standard local user can overwrite any DLL in the service directory. On service restart, the OS loads the attacker's DLL before any managed code runs, executing arbitrary code as SYSTEM."}],"cve":"CVE-2026-16157","ids":[{"system_name":"CERT/CC V Identifier ","text":"VU#847406"}]}],"product_tree":{"branches":[]}}