/Vulnerability Library

Kopia Server 0.23.0 - Remote Code Execution

CVE-2026-45695
Verified

Description

Kopia before version 0.23.0 allows unauthenticated remote code execution when started in server mode with the --without-password flag. When the /api/v1/repo/exists endpoint is exposed, it enables instantiation of the SFTP storage backend with user-supplied sshArguments. Due to improper argument parsing, an attacker may inject arbitrary SSH options such as -oProxyCommand, resulting in execution of arbitrary commands as the server process.

Severity

Critical

CVSS Score

9.8

Exploit Probability

2%

Affected Product

kopia

Published Date

June 19, 2026

Template Author

kenlacroix

CVE-2026-45695.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-45695
CWE ID:
cwe-88

References

https://github.com/kopia/kopia/security/advisories/GHSA-2q4c-3mrw-63c3https://github.com/kopia/kopia/pull/5354https://orca.security/resources/blog/kopia-backup-rce-vulnerability/https://nvd.nist.gov/vuln/detail/CVE-2026-45695

Remediation Steps

Upgrade to Kopia 0.23.0 or later, which refuses to bind an unauthenticated server to a non-loopback address. Do not expose the server with --without-password on untrusted networks.