Kopia disclosed CVE-2026-45695, a critical unauthenticated remote code execution flaw affecting versions before 0.23.0. The bug can be triggered when the backup tool's HTTP server is started with --without-password, allowing unauthenticated requests to /api/v1/repo/exists to pass attacker-controlled SFTP settings into backend storage handling. If externalSSH is enabled and sshArguments includes a malicious -oProxyCommand value, Kopia can invoke ssh in a way that leads to arbitrary command execution on the host. The issue carries a CVSS 9.8 rating and can expose confidentiality, integrity, and availability to full compromise.
The project fixed the vulnerability in version 0.23.0 and also added safeguards to prevent insecure unauthenticated servers from being exposed on non-loopback interfaces by default. A related code change restricts use of --insecure together with --without-password to loopback addresses or Unix sockets unless operators explicitly set the hidden override flag --allow-extremely-dangerous-unauthenticated-server-on-the-network, which warns that remote attackers could gain full control of the server host. Maintainers advised users to upgrade and ensure the HTTP server is protected with a password rather than exposed unauthenticated on the network.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The vulnerability record states that Kopia fixed CVE-2026-45695 in version 0.23.0. It also recommends upgrading and ensuring the HTTP server is started with a password as mitigation.
CVE-2026-45695 was disclosed as a critical unauthenticated remote code execution vulnerability in Kopia affecting versions prior to 0.23.0. The issue involves attacker-controlled SFTP configuration reaching blob.NewStorage and triggering command execution through OpenSSH ProxyCommand when externalSSH is enabled.
A Kopia code change added validation to block starting the server with both --insecure and --without-password on non-loopback network interfaces unless an explicit dangerous override flag is used. The change also added tests and warnings that remote attackers could gain full control of the host if such a server is exposed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.