Skip to main content
QUIETLYTIC
Vulnerability

Kopia Command Injection (CVE-2026-45695)

CVE-2026-45695 is a CVSS 9.8 OS command injection flaw enabling unauthenticated RCE in the Kopia backup tool before 0.23.0, reported exploited by VulnCheck KEV.

CVE-2026-45695
Threat Level
CRITICAL
CVSS
9.8
Status
Active Exploitation
Confidence
Medium
Affected Products
Kopia, kopia Kopia (before 0.23.0)

CVE-2026-45695 carries a CVSS 3.1 base score of 9.8 against Kopia, a cross-platform backup tool for Windows, macOS, and Linux offering incremental backups, client-side end-to-end encryption, and deduplication. NVD classifies it under two weaknesses — CWE-78 (OS Command Injection) and CWE-306 (Missing Authentication for Critical Function) — and states the issue is fixed in version 0.23.0, meaning releases before that version are affected. VulnCheck’s KEV feed reports the CVE as exploited, dated September 10, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-45695 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description lays out a specific, multi-step chain rather than a single defect. Kopia’s HTTP server, when started with the --without-password flag, accepts unauthenticated requests to its /api/v1/repo/exists endpoint. That endpoint forwards attacker-supplied SFTP storage configuration to Kopia’s blob.NewStorage function without adequate validation. Within that configuration, setting externalSSH: true and supplying sshArguments containing -oProxyCommand=<cmd> causes Kopia’s exec.CommandContext("ssh") call to invoke the attacker’s command through OpenSSH’s own ProxyCommand option — a legitimate OpenSSH feature (intended to let a connection route through an intermediate proxy command) repurposed as an arbitrary-command-execution primitive because Kopia passes attacker-controlled SSH arguments straight through to the ssh binary.

The --without-password precondition matters for scoping exposure: this is an operator-chosen startup flag, not Kopia’s default behavior. A Kopia HTTP server run with its normal password protection is not exposed through this specific path; one started without a password — a configuration a deployment might choose for internal-network convenience or CI/CD integration — is fully exposed to any network client that can reach the /api/v1/repo/exists endpoint.

Evidence and confidence

  • Medium confidence — the CVSS 9.8 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the dual CWE-78/CWE-306 classification, the full mechanism (the --without-password precondition, the vulnerable endpoint, the SFTP-configuration path, and the ProxyCommand execution primitive), and the 0.23.0 fixed version all trace to NVD alone. The exploitation report traces to VulnCheck KEV alone.
  • Unknown-leaning — exploitation probability. FIRST’s EPSS model scores this CVE 0.0161, 74.7th percentile as of our ingestion — comfortably above the midpoint of the broader EPSS population, though EPSS remains a predictive score rather than exploitation confirmation.

No field is in conflict between our two sources. NVD’s own record is unusually specific about mechanism for a vulnerability at this severity — most CVEs in our recent KEV batches name a function or endpoint; this one traces the full path from HTTP request to shell command.

Why this matters

Backup software occupies a privileged position by design: it needs broad filesystem read access and, for restore operations, write access, and it is frequently run with elevated permissions or as a scheduled service that nobody actively watches day to day. An unauthenticated RCE reachable through a backup tool’s own management API turns that trusted position into an attacker’s foothold — and because the exploitation path goes through a legitimate OpenSSH feature rather than a memory-safety bug, it will not be caught by tooling looking for the more familiar signatures of buffer overflows or deserialization gadgets.

The --without-password precondition is the single most actionable fact here: any Kopia HTTP server operator should confirm password protection is enabled as a first step, independent of and faster than a version upgrade. That said, NVD’s description states the outcome as unauthenticated remote code execution under that configuration, which is sufficient grounds to upgrade to 0.23.0 regardless of KEV status. The VulnCheck listing adds a real, if single-sourced, signal that this specific chain has moved from advisory to observed exploitation.

Frequently Asked Questions

What is CVE-2026-45695? A CVSS 9.8 OS command injection vulnerability (CWE-78 / CWE-306) in Kopia, a cross-platform backup tool, that NVD states allows unauthenticated remote code execution via a crafted SFTP storage configuration in versions before 0.23.0.

Is CVE-2026-45695 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 10, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration. Treat it as reported exploitation, not confirmed.

Do I need to have a specific configuration for my Kopia server to be at risk? Yes. NVD’s description specifies the server must be started with the --without-password flag, which disables Kopia’s normal HTTP authentication. A password-protected Kopia HTTP server is not exposed through this specific path.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed. The severity case for upgrading stands independently.

What should I do immediately, before upgrading? Confirm any Kopia HTTP server in your environment is not running with --without-password. That configuration check is faster than a version upgrade and addresses the specific precondition NVD’s advisory describes, though upgrading to 0.23.0 remains the complete fix.

Is authentication required to exploit this? No, when the server runs with --without-password. NVD’s vector records no required privileges or user interaction, consistent with that configuration.


Severity, vector, weakness classification, full exploitation mechanism, and fixed version sourced from the National Vulnerability Database record for CVE-2026-45695, which links Kopia’s own GitHub security advisory and the fixing commit. Exploitation status and the September 10, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools