Critical Backup Flaws Expose Vitess Environments to Complete Takeover
ID: 03362d27-65dc-5cbf-87e6-1b436aea338c
STIX ID: report--03362d27-65dc-5cbf-87e6-1b436aea338c
Feed Name: securityonline.info
Threat Score
Two high-severity vulnerabilities in Vitess allow an attacker who can modify backup storage (e.g., an S3 bucket) to poison backup manifest files so that restored backups write files to arbitrary locations (CVE-2026-27969, path traversal) or execute arbitrary commands during restore (CVE-2026-27965); maintainers have released fixes (v23.0.3 / v22.0.4) and administrators should secure decompression settings as an interim mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
