Arbitrary Command Execution Vulnerability in btrbk Backup Tool by Digint
CVE-2026-62943

8.7HIGH

Key Information:

Vendor

Digint

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-62943?

The btrbk backup tool's ssh_filter_btrbk.sh script, versions 0.29.0 through 0.32.7, contains a vulnerability allowing users with restricted access via authorized_keys to execute arbitrary commands. This occurs due to a flaw in the command structure that permits appending additional commands after a valid btrbk command prefix, bypassing intended restrictions. This security risk is mitigated in version 0.32.7.

Affected Version(s)

btrbk >= 0.29.0, < 0.32.7

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.