HIGHCVE-2026-22676Published Modified CNA VulnCheck
CVE-2026-22676: Barracuda RMM < 2025.2.2 Privilege Escalation via Insecure Directory Permissions
Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gain SYSTEM-level privileges by exploiting overly permissive filesystem ACLs on the C:\Windows\Automation directory. Attackers can modify existing automation content or place attacker-controlled files in this directory, which are then executed under the NT AUTHORITY\SYSTEM account during routine automation cycles, typically succeeding within the next execution cycle.
Metrics
- CVSS v4.0
- 8.5
- Severity
- HIGH
- Fixed in
- 2025.2.2
- Affected Products
- 1
Affected packages
- Barracuda Networks / RMM< 2025.2.2 (from 0)
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N