CVE-2026-4822 PUBLISHED

Enter Software Iperius Backup Backup Service Local Privilege Escalation

Assigner: VulDB
Reserved: 25.03.2026 Published: 25.03.2026 Updated: 25.03.2026

A vulnerability was detected in Enter Software Iperius Backup bis 8.7.3. Affected is an unknown function of the file C:\ProgramData\IperiusBackup\Jobs\ of the component Backup Service. Performing a manipulation results in creation of temporary file with insecure permissions. The attack is only possible with local access. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The exploit is now public and may be used. Upgrading to version 8.7.4 is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
CVSS Score: 7.3

Product Status

Vendor Enter Software
Product Iperius Backup
Versions
  • Version 8.7.0 is affected
  • Version 8.7.1 is affected
  • Version 8.7.2 is affected
  • Version 8.7.3 is affected
  • Version 8.7.4 is unaffected

Credits

  • 0truust (VulDB User) reporter
  • VulDB coordinator

References

Problem Types

  • Creation of Temporary File With Insecure Permissions CWE
  • Insecure Temporary File CWE