Security Advisory

CVE-2026-22676

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-04-15 20:45:23
Last updated 2026-04-16 12:05:01
Assigner VulnCheck
State PUBLISHED

Description

Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gain SYSTEM-level privileges by exploiting overly permissive filesystem ACLs on the C:WindowsAutomation directory. Attackers can modify existing automation content or place attacker-controlled files in this directory, which are then executed under the NT AUTHORITYSYSTEM account during routine automation cycles, typically succeeding within the next execution cycle.