How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Critical Unauthenticated RCE in Kopia Backup via SSH ProxyCommand Injection

calendar_today May 26, 2026 person The Orca Security Team domain orca-security

A critical vulnerability (CVE-2026-45695, CVSS 9.8) was disclosed affecting Kopia, the open-source backup and restore tool, allowing attackers to achieve unauthenticated remote code execution via SSH command-line argument injection. Due to the potential for full system compromise without any authentication, immediate patching is required. Technical Overview The issue originates from Kopia’s HTTP server API endpoint […] The post Critical Unauthenticated RCE in Kopia Backup via SSH ProxyCommand Injection appeared first on Orca Security .

open_in_new Read original post