CVE-2026-45695Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to 0.23.0, Kopia's HTTP server started with --without-password accepts unauthenticated requests to /api/v1/repo/exists and forwards attacker-supplied SFTP storage configuration to blob.NewStorage, where externalSSH: true and sshArguments containing -oProxyCommand=<cmd> can cause exec.CommandContext("ssh") to invoke the command through OpenSSH. This issue is fixed in version 0.23.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 9 signals
  • Disclosure: 6 classified signals
  • Peaked 1d ago at 4 mentions (2026-06-07); latest day: 1
  • 9 total mentions across 5 days

Deep dive

Activity timeline9 mentions / 5d
01234Mentions · 2026-05-20: 1Mentions · 2026-05-25: 2Mentions · 2026-05-26: 1Mentions · 2026-06-07: 4Mentions · 2026-08-21: 1PoC Mentioned / Linked · 2026-05-25: 1PoC Mentioned / Linked · 2026-08-21: 1Patch / Workaround · 2026-05-25: 1Patch / Workaround · 2026-05-26: 1Patch / Workaround · 2026-06-07: 2Technical Details · 2026-05-20: 1Technical Details · 2026-05-25: 2Technical Details · 2026-05-26: 1Technical Details · 2026-06-07: 4Technical Details · 2026-08-21: 105-2005-2505-2606-0708-21
Signal classification2 categories
Disclosure
666.7%
Patch
333.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-201
Disclosure1
2026-05-252
Disclosure1Patch1
2026-05-261
Disclosure1
2026-06-074
Disclosure2Patch2
2026-08-211
Disclosure1
Full discourse9 posts
  • Gray Hats@the_yellow_fall
    Patch

    A critical unauthenticated RCE flaw (CVE-2026-45695) impacts Kopia backup servers. Learn how the Kopia SSH ProxyCommand injection exploit operates and how to patch it. #Cybersecurity #BackupSecurity #RCE #Kopia #Infosec #PatchNow https://securityonline.info/kopia-ssh-proxycommand-injection-rce/ https://t.co/dQflyeRmIS

    Post summary

    The tweet announces a critical unauthenticated RCE flaw (CVE-2026-45695) in Kopia backup servers, explains the SSH ProxyCommand injection mechanism, and provides instructions for patching.

    0902973.5K
    12.5K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-45695 - critical 🚨 Kopia Server 0.23.0 - Remote Code Execution &gt; Kopia before version 0.23.0 allows unauthenticated remote code execution when started... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-45695 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces a critical remote code execution vulnerability in Kopia Server (pre-0.23.0), linking to a CVE library entry while providing technical details but not offering exploit code or evidence of active exploitation.

    00093671
    1.3K followersView on X
  • Orca Security@orcasec
    Disclosure

    🚨 Critical Unauthenticated RCE in Kopia Backup A critical vulnerability, CVE-2026-45695 (CVSS 9.8), affects Kopia's HTTP server v0.22.3 and earlier. One unauthenticated HTTP request = arbitrary code execution. Upgrade to v0.23.0 now. 👉 https://orca.security/resources/blog/kopia-backup-rce-vulnerability/?utm_source=twitter&utm_medium=organic+social&utm_campaign=orca+blog https://t.co/7gPLjTdwnL

    Post summary

    The tweet discloses a critical RCE vulnerability (CVE-2026-45695) in Kopia v0.22.3 with a high CVSS score and recommends upgrading to v0.23.0 to mitigate the risk.

    01020191
    4.8K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - Kopia RCE via SSH ProxyCommand Injection (CVE-2026-45695) Kopia's HTTP server started with --without-password accepts unauthenticated requests. When using an SFTP backend with externalSSH: true, an attacker can inject -oProxyCommand= through sshArguments in the storage configuration. OpenSSH executes the command via shell before attempting any connection. 👉Affected: kopia <= 0.22.3

    Post summary

    The post announces a critical RCE vulnerability in Kopia (CVE-2026‑45695), detailing how an unauthenticated attacker can inject SSH proxy commands via the storage configuration, affecting versions <=0.22.3. No PoC, exploit code, active exploitation reports, or patch information are mentioned.

    00020157
    255 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Full Tweet A critical unauthenticated RCE flaw (CVE-2026-45695) impacts Kopia backup servers. Learn how the Kopia SSH ProxyCommand injection exploit operates and how to patch it.

    Post summary

    The tweet announces a critical RCE vulnerability (CVE‑2026‑45695) in Kopia backup servers, explains that it involves SSH ProxyCommand injection, and urges users to apply the available patch.

    1000027
    253 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Source: X search for RCE 2026 exploit Posted: 2026-05-25T02:02:00.000Z Likes: 13 0day Intel: A critical unauthenticated RCE flaw (CVE-2026-45695) impacts Kopia backup server

    Post summary

    A newly identified critical unauthenticated RCE flaw, CVE-2026-45695, affects the Kopia backup server; no PoC, exploit code, or patch details are provided.

    1000038
    253 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    CVE-2026-45695: A critical unauthenticated RCE flaw (CVE-2026-45695) impacts Kopia backup servers. Learn how the Kopia SSH ProxyCommand injection exploit operates and how to patch it. #Cybersecurity #BackupSecurity #RCE #Kopia #Infosec #PatchNow

    Post summary

    The post highlights a critical unauthenticated RCE flaw (CVE‑2026‑45695) in Kopia backup servers and focuses on how users can patch the vulnerability.

    1000034
    253 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    0day Intel: A critical unauthenticated RCE flaw (CVE-2026-45695) impacts Kopia backup server

    Post summary

    A new critical unauthenticated RCE vulnerability (CVE-2026-45695) affecting the Kopia backup server has been disclosed.

    1000044
    253 followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    CVE-2026-45695 - CVSS 9.8 unauthenticated RCE in Kopia's backup HTTP server. No credentials needed. ProxyCommand injection via a crafted storage config. The server you'd rely on after a ransomware hit. https://purple-ops.io/blog/kopia-unauthenticated-rce-cve-2026-45695 https://t.co/opXF8bZE8u

    Post summary

    A high‑severity unauthenticated RCE vulnerability in Kopia’s HTTP backup server is disclosed, detailing its CVSS score, exploitation vector, and linking to a blog likely containing PoC content, but with no evidence of active exploitation or available fix.

    00010146
    575 followersView on X

Explore more