CVE-2026-22676

7.8

Barracuda Networks · RMM

Barracuda RMM prior to 2025.2.2 contains a privilege escalation vulnerability due to insecure filesystem permissions in the C:\Windows\Automation directory, allowing local SYSTEM-level execution.

Executive summary

A privilege escalation vulnerability in Barracuda RMM allows local attackers to achieve SYSTEM-level execution by exploiting insecure directory permissions.

Vulnerability

The software suffers from an incorrect permission assignment for critical resources (CWE-732). An authenticated local user can modify files within the C:\Windows\Automation directory, which are subsequently executed with NT AUTHORITY\SYSTEM privileges during standard maintenance cycles.

Business impact

The ability for a local user to escalate privileges to SYSTEM level represents a total compromise of the affected host. An attacker could install persistent backdoors, disable security software, or exfiltrate sensitive data managed by the RMM platform. Given the CVSS score of 7.8, this vulnerability poses a significant risk to the integrity and confidentiality of the entire managed environment.

Remediation

Immediate Action: Upgrade Barracuda RMM to version 2025.2.2 or later immediately to apply the corrected filesystem access control lists.

Proactive Monitoring: Review system logs for unauthorized modifications to the C:\Windows\Automation directory and monitor for unusual process creation events originating from that path.

Compensating Controls: Restrict local user access to the affected directory via Group Policy Objects (GPO) until the patch can be deployed across the environment.

Exploitation status

Public Exploit Available: No confirmed public exploit exists in the provided data.

Analyst recommendation

This vulnerability presents a severe risk by providing a direct path to full system control for local attackers. IT and security teams must prioritize the deployment of the 2025.2.2 update to remediate the insecure directory permissions. Failure to patch allows for potential lateral movement and persistence if an attacker gains an initial foothold on a managed endpoint.

Sources