logo

CVE-2026-45695: Kopia Backup Tool Exposes Unauthenticated HTTP API

ID: 5f12e15c-ceee-521e-afef-d4dc4ec87740

STIX ID: report--5f12e15c-ceee-521e-afef-d4dc4ec87740

Feed Name: CosmicBytez Labs

Threat Score
80/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

...
...

## Executive Summary CVE-2026-45695 is a critical authentication bypass in Kopia's HTTP server when started with the --without-password flag, allowing unauthenticated network clients to access endpoints (notably /api/v1/repo/exists) and potentially enumerate, read, or manipulate backup repositories; the flaw affects Kopia versions prior to 0.23.0 and is fixed in 0.23.0, with recommended mitigations including upgrading, avoiding --without-password on network-accessible services, binding to loopback, and firewalling the service.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.