216.73.216.226

CVE-2026-22676

· Published 15/04/2026 21:17 · Modified 15/04/2026 21:17

Labels: CVE-2026-22676 2026-04-15CVE-2026-22676CWE-732[email protected]

Essential information

Published
15/04/2026 21:17
Modified
15/04/2026 21:17
Author
Creator
CVSS
8.5 HIGH (v3) 8.5 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gain SYSTEM-level privileges by exploiting overly permissive filesystem ACLs on the C:\Windows\Automation directory. Attackers can modify existing automation content or place attacker-controlled files in this directory, which are then executed under the NT AUTHORITY\SYSTEM account during routine automation cycles, typically succeeding within the next execution cycle.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
barracuda / rmm cpe:2.3:a:barracuda:rmm:<2025.2.2:*:*:*:*:*:*:*

References