Critical Unauthenticated RCE Flaw Threatens Kopia Backup Servers
ID: f2e536cb-0fe2-524a-9f88-aaa82bce9293
STIX ID: report--f2e536cb-0fe2-524a-9f88-aaa82bce9293
Feed Name: securityonline.info
Kopia contains a critical RCE vulnerability (CVE-2026-45695) in its HTTP server where unauthenticated attackers can inject an -oProxyCommand token into storage configuration fields (e.g., via the /api/v1/repo/exists endpoint when the server is started with --without-password and uses SFTP/SSH backends), allowing arbitrary command execution as the Kopia process user; organizations should immediately apply the provided patch, avoid starting servers without passwords, and restrict exposure to non-loopback interfaces.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
