CVE-2026-26225

Intego Personal Backup, a macOS backup utility that allows users to create scheduled backups and bootable system clones, contains a local privilege escalation vulnerability. Backup task definitions are stored in a location writable by non-privileged users while being processed with elevated privileges. By crafting a malicious serialized task file, a local attacker can trigger arbitrary file writes to sensitive system locations, leading to privilege escalation to root.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-02-12 22:16

Updated : 2026-02-13 14:23


NVD link : CVE-2026-26225

Mitre link : CVE-2026-26225

CVE.ORG link : CVE-2026-26225


JSON object : View

Products Affected

No product.

CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')