Junglewise Threat Intelligence

CVE-2026-13268: G DATA Total Security link following privilege escalation in Backup Service

CVE-2026-13268 · Severity: high · CVSS 7.8 · Published 2026-07-29

Technologies: G DATA Total Security.

Executive brief

A vulnerability in G DATA Total Security's backup component could allow a user with limited access to a computer to gain full administrative control. By manipulating how the software handles file shortcuts during backup operations, an attacker can delete protected files and execute their own code with the highest level of system permissions. This could lead to a complete compromise of the affected machine, including the theft of sensitive data or the disabling of security protections.

Technical details

A local privilege escalation vulnerability exists in the G DATA Total Security Backup Service due to improper link resolution (CWE-59). The flaw occurs when the service processes file operations, allowing a low-privileged attacker to create symbolic links that redirect the service's file deletion actions to unintended locations. By exploiting this link-following behavior, an attacker can delete sensitive system files or manipulate the environment to achieve arbitrary code execution with SYSTEM privileges. The attack requires the adversary to already have local code execution capabilities on the target host. The vulnerability is addressed in version 25.5.20.121.

Affected products

  • G DATA Total Security 25.5.19.439

Timeline

  • 2026-02-12: disclosed: Vulnerability reported to vendor
  • 2026-07-15: patched: Fixed in version 25.5.20.121
  • 2026-07-15: advisory: Coordinated public release of advisory ZDI-26-432

References