By NHI Mgmt Group Editorial TeamBased on Orca Security: “Critical Unauthenticated RCE in Kopia Backup via SSH ProxyCommand Injection” (May 26, 2026)

TL;DR: A CVE-2026-45695 flaw in Kopia allows unauthenticated remote code execution through SSH argument injection when the server runs in passwordless mode and exposes an SFTP backend, according to Orca Security. Backup infrastructure that assumes internal reachability is enough to justify weak authentication now needs a stricter identity and exposure model.


At a glance

What this is: This is a critical Kopia vulnerability that lets an unauthenticated attacker trigger remote code execution through SSH command-line argument injection in exposed backup servers.

Why it matters: It matters because backup infrastructure often holds broad trust and broad data access, so a single unauthenticated RCE can turn a recovery tool into an enterprise-wide compromise path.

By the numbers:

  • Kopia vulnerability CVE-2026-45695 carries a CVSS score of 9.8.
  • The issue affects Kopia HTTP server versions 0.22.3 and earlier.

Context

Kopia is a backup and restore tool, but in this case the security boundary is not backup content alone. The article describes a network-reachable HTTP API that passes user-controlled storage fields into an SSH command line, which means command construction becomes part of the attack surface.

The identity governance problem is straightforward: a service that is often treated as low-friction infrastructure can become a privileged control plane when it can read repositories, reach SFTP backends, and execute commands before authentication. In that state, exposure and trust assumptions matter more than the backup label.

The source says some administrators run Kopia in passwordless mode for convenience, especially in internal environments. That posture is common enough to be credible, but it is also exactly the kind of configuration that turns a backup service into an externally reachable identity and execution risk.


Key questions

Q: What breaks when a backup server accepts unauthenticated requests and passes them into SSH arguments?

A: The trust boundary breaks first, then the service becomes a remote code execution path. If configuration fields are copied into shell or SSH arguments without strict parsing, an attacker can inject commands before any intended backup workflow runs. In practice, that turns a backup utility into privileged host access and a likely path to data exposure.

Q: Why does a passwordless backup server create such high compromise risk?

A: Because passwordless mode removes the control that blocks unauthorised callers from reaching the parser and its downstream command execution path. Once the service is network reachable, the attacker needs only a crafted request. The risk is high because the same process that manages backups can also expose data and execute arbitrary commands.

Q: How do security teams know whether backup tooling is safe to expose on a network?

A: They should test whether the service can be reached without an external authentication gate, whether it passes user input into shell-like tooling, and whether insecure startup flags are permitted in production. If any of those conditions are true, the service should be treated as an exposed privilege boundary rather than routine infrastructure.

Q: Should organisations prefer localhost binding or an authenticating reverse proxy for backup servers?

A: Use both as layered controls, but if a backup service must remain network accessible, an authenticating reverse proxy is the stronger compensating gate. Localhost binding is the safest default for administration-only use, while network exposure should be reserved for cases where strong authentication and tight configuration control are already in place.


Technical breakdown

How SSH argument injection turns a backup API into code execution

The vulnerability sits in Kopia’s /api/v1/repo/exists endpoint, where storage configuration fields are inserted into an SSH command line. If input is split only on literal spaces and not tokenised safely, an attacker can smuggle options such as -oProxyCommand and change the meaning of the command before SSH ever connects. That bypasses the intended SFTP workflow entirely. This is not a protocol flaw in SSH itself, but a failure to treat command construction as an untrusted boundary. Once shell-adjacent arguments are attacker controlled, remote execution becomes a parsing problem rather than a network-authentication problem.

Practical implication: treat any API that builds commands from configuration input as code-execution sensitive and remove that trust path.

Why passwordless backup servers are exposure multipliers

The article’s key precondition is Kopia running with the --without-password flag on a non-loopback interface. That matters because authentication is not just an access gate here, it is the control that prevents an attacker from reaching the vulnerable parser at all. When the service is reachable over the network and exposed behind only convenience assumptions, the backup server becomes remotely actionable infrastructure. In NHI terms, the service identity has been given operational reach without sufficient boundary checks, so the attack surface is defined by exposure plus privilege, not by data sensitivity alone.

Practical implication: constrain network reachability before relying on the service’s own authentication model.

Why command-line parsing needs strict allowlists in restore tooling

Kopia’s issue comes from insufficient validation of SFTP-related fields and a lack of strict token handling, quote handling controls, and allowlists. Restore and backup platforms often need to interact with SSH, object storage, and remote endpoints, which tempts developers to pass user input directly into tooling. That pattern is unsafe because infrastructure configuration looks benign until it is reinterpreted as executable syntax. The control failure is not merely missing sanitisation in one field; it is the absence of a safe construction model for high-trust operational commands.

Practical implication: use allowlisted parameters and safe command construction wherever backup software calls external binaries.


Threat narrative

Attacker objective: The attacker aims to execute arbitrary commands on the backup server and use that position to access backup data or move deeper into the environment.

  1. Entry occurs through a single crafted HTTP request to the exposed /api/v1/repo/exists endpoint, with no authentication required when the server is reachable on the network in passwordless mode.
  2. Credential or privilege abuse is unnecessary because the attacker leverages SSH ProxyCommand injection through storage configuration fields, causing OpenSSH to execute arbitrary commands.
  3. Impact is full compromise of the Kopia process context, with potential access to backup data and possible pivoting into adjacent infrastructure.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Unauthenticated backup-server access is a governance failure, not just a vulnerability class. The article shows that when a backup service is bound to the network without a compensating authentication layer, the service itself becomes the access path. That is an identity boundary problem because the server is trusted to act on storage and SSH instructions before proving who is calling it. Practitioners should treat exposed backup controls as privileged control planes, not passive infrastructure.

Command construction from user-controlled fields creates an identity collapse between configuration and execution. In this case, storage settings are effectively reinterpreted as executable SSH syntax. That means least privilege at the service layer is undermined by parser behaviour, because the attacker does not need legitimate access to the backup content, only a way to shape the command line. The named concept here is parser-to-execution trust debt: every field passed into external tooling inherits the power of that tool. Security teams need to recognise that debt before it becomes remote code execution.

Passwordless operation on network-facing backup tools is a standing privilege pattern. The article is not describing an exotic exploit chain. It is describing an everyday convenience configuration that removes the one control that would have blocked the request path. That makes this a familiar NHI governance failure mode: access assumptions are made at deployment time and then left to persist in production. The implication is that network reachability and authentication state must be governed together, not separately.

Backup systems require exposure-based governance, not tool-based trust. A tool that handles backup data is often assumed to be safe because its purpose is defensive. This case shows that purpose does not reduce attack surface when the application can call SSH, reach SFTP backends, and execute commands. The broader lesson is that identity and access decisions must follow runtime exposure and integration points, not product category. Practitioners should reclassify backup servers according to the privileges they hold, not the jobs they perform.

Full compromise risk is what happens when operational convenience outruns control design. Orca Security’s disclosure indicates that attackers can pivot from a single request to arbitrary command execution and then to backup-data exposure or broader infrastructure compromise. That is the practical end state of weak boundary design in NHI-adjacent infrastructure. The corrective lens is simple: if a system can execute commands as part of its normal work, it needs the same governance attention as any other privileged execution path.

What this signals

Parser-to-execution trust debt: backup platforms that translate user-controlled repository settings into command-line arguments inherit the full risk of that parser boundary. Once that boundary is crossed, authentication posture and network exposure matter as much as the backup function itself.

Orca Security's disclosure reinforces a broader programme lesson for identity and infrastructure teams: convenience modes that suppress authentication create standing privilege in disguise. The control question is not whether the service is internal, but whether it can be reached and directed without an explicit trust gate.


For practitioners

  • Audit exposed backup services Inventory backup and restore systems that are reachable beyond localhost and identify any deployment that relies on passwordless operation for convenience.
  • Remove command-line trust from configuration input Review any backup workflow that passes storage or repository fields into SSH or other external binaries, and replace free-form parsing with strict allowlists and safe argument handling.
  • Enforce authentication before network exposure Place externally reachable backup services behind an authenticating reverse proxy or equivalent access gate, and do not rely on internal network placement as a control.
  • Upgrade vulnerable Kopia instances immediately Move affected deployments to version 0.23.0 or later, then verify that insecure and passwordless server modes cannot start on non-loopback interfaces.

Key takeaways

  • The Kopia flaw shows that a backup server can become a remote code-execution surface when configuration fields are allowed to shape SSH commands.
  • The article ties exploitation to exposed deployments, passwordless operation, and unsafe argument handling, which together remove the normal trust boundaries around backup infrastructure.
  • The limiting control is not one more patch alone, but a stricter exposure model that combines authenticated access, safe parsing, and non-networked defaults.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationPasswordless network exposure leaves the backup service reachable without an auth gate.
NHI-06 — Insecure Cloud Deployment ConfigurationsThe flaw becomes reachable when Kopia is deployed with unsafe exposure and backend settings.
Recommendation — Require authenticated access before exposing backup services on any non-loopback interface. Harden backup deployments so insecure server modes cannot run on externally reachable interfaces.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe attack path aims to turn a backup server into a foothold for deeper compromise.
Recommendation — Map exposed backup-server exploits to credential access and lateral movement hunt paths.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe issue is an access-control failure at a privileged service boundary.
Recommendation — Enforce permissions and authorization gates before backup APIs can reach command execution.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementPasswordless operation is the core condition that removes the protective authentication barrier.
Recommendation — Use authenticator management controls to prevent passwordless exposure on network-facing services.

Key terms

  • Command injection: Command injection occurs when attacker-controlled data is inserted into a shell command and changes what the process executes. In AI tooling, that often happens through wrappers, plugins, or installation flows that turn paths or prompts into shell strings. The impact is privilege abuse through the process’s inherited authority.
  • Passwordless Exposure: Passwordless exposure is a deployment state where a service can be reached over the network without an authentication gate. In identity terms, it creates standing access that is controlled by topology instead of credentials, which is fragile for privileged infrastructure.
  • ProxyCommand: ProxyCommand is the older OpenSSH mechanism for opening a connection through an intermediate host by running an arbitrary command. It is more flexible than ProxyJump, but also more verbose and harder to maintain. Teams usually prefer it only when they need a custom transport or nonstandard connection flow.
  • Privileged Access Control Plane: The privileged access control plane is the layer that governs how elevated access is requested, approved, issued, monitored, and revoked. It coordinates policy, identity, session control, and audit for privileged users and NHI, enforcing who can perform sensitive actions, under what conditions, and with what traceability across systems.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org