CVE-2022-50688: Cobiansoft Cobian Backup Gravity
High severity, CVSS 8.4. EPSS: 0.1% chance of exploitation in the next 30 days.
Cobian Backup Gravity 11.2.0.582 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the CobianBackup11 service to inject malicious code that would execute with LocalSystem privileges during service startup.
Affected products
- Cobiansoft Cobian Backup Gravity: version 11.2.0.582 only
Published 2025-12-22. Last modified 2026-06-17.