{"id":"CVE-2026-22676","title":"Barracuda RMM < 2025.2.2 Privilege Escalation via Insecure Directory Permissions","summary":"Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gain SYSTEM-level privileges by exploiting overly permissive filesystem ACLs on the C:\\Windows\\Automation directory. Att…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","cwe":["CWE-732"],"vendor":"Barracuda Networks","product":"RMM","affected":["RMM < 2025.2.2"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-04-16T11:21:11.940885Z"},"published":"2026-04-15","updated":"2026-10-01","sourceUpdated":"2026-10-01T15:19:48.445Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-22676","references":[{"url":"https://download.mw-rmm.barracudamsp.com/PDF/2025.2.2/RN_BRMM_2025.2.2_EN.pdf"},{"url":"https://www.vulncheck.com/advisories/barracuda-rmm-privilege-escalation-via-insecure-directory-permissions"}],"tags":["cve.org"],"epss":0.00104,"epssPercentile":0.0096,"ingestedAt":"2026-10-01T15:48:17.869Z","slug":"CVE-2026-22676","body":"## Overview\n\nBarracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gain SYSTEM-level privileges by exploiting overly permissive filesystem ACLs on the C:\\Windows\\Automation directory. Attackers can modify existing automation content or place attacker-controlled files in this directory, which are then executed under the NT AUTHORITY\\SYSTEM account during routine automation cycles, typically succeeding within the next execution cycle.\n\n## Affected\n\n- `RMM < 2025.2.2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}