CVE-2026-45695: Kopia Backup Tool Exposes Unauthenticated HTTP API
ID: 5f12e15c-ceee-521e-afef-d4dc4ec87740
STIX ID: report--5f12e15c-ceee-521e-afef-d4dc4ec87740
Feed Name: CosmicBytez Labs
## Executive Summary CVE-2026-45695 is a critical authentication bypass in Kopia's HTTP server when started with the --without-password flag, allowing unauthenticated network clients to access endpoints (notably /api/v1/repo/exists) and potentially enumerate, read, or manipulate backup repositories; the flaw affects Kopia versions prior to 0.23.0 and is fixed in 0.23.0, with recommended mitigations including upgrading, avoiding --without-password on network-accessible services, binding to loopback, and firewalling the service.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
