Kopia Server 0.23.0 - Remote Code Execution
CVE-2026-45695
Verified
Description
Kopia before version 0.23.0 allows unauthenticated remote code execution when started in server mode with the --without-password flag. When the /api/v1/repo/exists endpoint is exposed, it enables instantiation of the SFTP storage backend with user-supplied sshArguments. Due to improper argument parsing, an attacker may inject arbitrary SSH options such as -oProxyCommand, resulting in execution of arbitrary commands as the server process.
Severity
Critical
CVSS Score
9.8
Exploit Probability
2%
Affected Product
kopia
Published Date
June 19, 2026
Template Author
kenlacroix
CVE-2026-45695.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-45695
CWE ID:
cwe-88
Remediation Steps
Upgrade to Kopia 0.23.0 or later, which refuses to bind an unauthenticated server to a non-loopback address. Do not expose the server with --without-password on untrusted networks.