CVE-2019-15720: Cloudberrylab Backup

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

CloudBerry Backup v6.1.2.34 allows local privilege escalation via a Pre or Post backup action. With only user-level access, a user can modify the backup plan and add a Pre backup action script that executes on behalf of NT AUTHORITY\SYSTEM.

Affected products

Published 2019-08-28. Last modified 2026-06-17.