Arbitrary Command Execution Vulnerability in btrbk Backup Tool by Digint
CVE-2026-62943
8.7HIGH
What is CVE-2026-62943?
The btrbk backup tool's ssh_filter_btrbk.sh script, versions 0.29.0 through 0.32.7, contains a vulnerability allowing users with restricted access via authorized_keys to execute arbitrary commands. This occurs due to a flaw in the command structure that permits appending additional commands after a valid btrbk command prefix, bypassing intended restrictions. This security risk is mitigated in version 0.32.7.
Affected Version(s)
btrbk >= 0.29.0, < 0.32.7
