Skip to content
CVE / MITRECVE RecentΒ·Β·1 min read

CVE-2026-45695 - Kopia: Unauthenticated RCE via SSH ProxyCommand Injection when --insecure --without-password is used

CVE ID :CVE-2026-45695 Published : July 16, 2026, 3:42 p. m. | 34 minutes ago Description :Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication.

Prior to 0. 23. 0, Kopia's HTTP server started with --without-password accepts unauthenticated requests to /api/v1/repo/exists and forwards attacker-supplied SFTP storage configuration to blob.

Originally reported by CVE Recent
0 comments

0 comments

Posting as FierceLynx257
0/1000

No comments yet. Be the first to start the discussion.