A critical remote code execution flaw tracked as CVE-2026-45695 affects Kopia Server versions up to 0.22.3, allowing unauthenticated attackers to execute commands through the POST /api/v1/repo/exists endpoint under specific configurations. The issue arises when Kopia is run with --without-password and uses an SFTP backend with externalSSH, letting attacker-controlled sshArguments be split on spaces and passed to SSH. By injecting -oProxyCommand, an attacker can cause SSH to invoke /bin/sh before a connection is established, leading to command execution with the privileges of the Kopia server process.
Public exploitation details and detection content were released alongside a Metasploit exploit module and a Nuclei template update, indicating rapid weaponization of the bug. Reported proof-of-concept testing against kopia/kopia:0.22.3 showed both timing-based validation and reverse-shell execution, while 0.23.0 is described as fixed or otherwise protected by refusing unauthenticated exposure on non-loopback interfaces. The vulnerability specifically impacts deployments that expose the affected endpoint without authentication and permit external SSH options in repository checks.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
A Rapid7 Metasploit Framework pull request added an exploit module for the Kopia Server SFTP ProxyCommand argument injection vulnerability, indicating public weaponization of the issue. The module targets unauthenticated command execution through the vulnerable /api/v1/repo/exists endpoint.
A ProjectDiscovery nuclei-templates pull request added detection content for CVE-2026-45695, documenting the vulnerable behavior and a timing-based exploitation check using a malicious SSH ProxyCommand argument. This reflects public technical detection guidance for the Kopia Server issue.
The references state that version 0.23.0 is the fixed or non-vulnerable release for CVE-2026-45695. One report notes that kopia/kopia:0.23.0 refuses unauthenticated exposure on non-loopback interfaces, preventing the demonstrated attack path.
Proof-of-concept exploitation was demonstrated against the kopia/kopia:0.22.3 container image, including timing-based command execution via a malicious -oProxyCommand value and a reverse shell demonstration. The reports indicate successful command execution through /bin/sh before SSH connection establishment.
A command injection vulnerability tracked as CVE-2026-45695 was identified in Kopia Server's POST /api/v1/repo/exists endpoint when using external SSH options, allowing attacker-controlled sshArguments to inject an SSH ProxyCommand and achieve unauthenticated remote code execution. The issue was reported as affecting versions up to 0.22.3, particularly when the server was exposed without password protection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.