- Description
- Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to 0.23.0, Kopia's HTTP server started with --without-password accepts unauthenticated requests to /api/v1/repo/exists and forwards attacker-supplied SFTP storage configuration to blob.NewStorage, where externalSSH: true and sshArguments containing -oProxyCommand=<cmd> can cause exec.CommandContext("ssh") to invoke the command through OpenSSH. This issue is fixed in version 0.23.0.
- Source
- security-advisories@github.com
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-78
- Hype score
- Not currently trending
CVE-2026-45695: A critical unauthenticated RCE flaw (CVE-2026-45695) impacts Kopia backup servers. Learn how the Kopia SSH ProxyCommand injection exploit operates and how to patch it. #Cybersecurity #BackupSecurity #RCE #Kopia #Infosec #PatchNow
@lyrie_ai
7 Jun 2026
22 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2026-45695 — Kopia Backup RCE, CVSS 9.8 Unauthenticated SSH ProxyCommand injection via HTTP API (port 51515). No creds needed. Kopia runs elevated — exploit = root. Patch immediately. #CVE #RCE #ThreatIntel #CVE202645695
@NoctisIntel
27 May 2026
76 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-45695: Critical RCE risk in Kopia. Unauthorized remote code execution may put backup environments, stored data, and connected systems at risk. 🔎 https://t.co/LGt8fzXtlW #CVE #Kopia #RCE #CyberSecurity #Vulert https://t.co/NyBzQOBBjQ
@vulert_official
20 May 2026
30 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes