logo

Critical Unauthenticated RCE Flaw Threatens Kopia Backup Servers

ID: f2e536cb-0fe2-524a-9f88-aaa82bce9293

STIX ID: report--f2e536cb-0fe2-524a-9f88-aaa82bce9293

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-05-25

Date Updated: 2026-05-25

Author: Ddos

...
...

Kopia contains a critical RCE vulnerability (CVE-2026-45695) in its HTTP server where unauthenticated attackers can inject an -oProxyCommand token into storage configuration fields (e.g., via the /api/v1/repo/exists endpoint when the server is started with --without-password and uses SFTP/SSH backends), allowing arbitrary command execution as the Kopia process user; organizations should immediately apply the provided patch, avoid starting servers without passwords, and restrict exposure to non-loopback interfaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.