Beveiligingsadvies

CVE-2026-22676

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-04-15 20:45:23
Laatst bijgewerkt 2026-04-16 12:05:01
Toegewezen door VulnCheck
CVSS-score 8.5
Status PUBLISHED

Beschrijving

Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gain SYSTEM-level privileges by exploiting overly permissive filesystem ACLs on the C:\Windows\Automation directory. Attackers can modify existing automation content or place attacker-controlled files in this directory, which are then executed under the NT AUTHORITY\SYSTEM account during routine automation cycles, typically succeeding within the next execution cycle.