Home

Description

Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gain SYSTEM-level privileges by exploiting overly permissive filesystem ACLs on the C:\Windows\Automation directory. Attackers can modify existing automation content or place attacker-controlled files in this directory, which are then executed under the NT AUTHORITY\SYSTEM account during routine automation cycles, typically succeeding within the next execution cycle.

PUBLISHED Reserved 2026-01-08 | Published 2026-04-15 | Updated 2026-04-16 | Assigner VulnCheck




HIGH: 8.5CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-732 Incorrect Permission Assignment for Critical Resource

Product status

Default status
unaffected

Any version before 2025.2.2
affected

References

download.mw-rmm.barracudamsp.com/.../RN_BRMM_2025.2.2_EN.pdf vendor-advisory patch

www.vulncheck.com/...tion-via-insecure-directory-permissions third-party-advisory

cve.org (CVE-2026-22676)

nvd.nist.gov (CVE-2026-22676)

Download JSON