Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-62943: btrbk backup tool lets SSH users run extra commands
CVE-2026-62943 · published 10 days ago
Summary
Versions 0.29.0 through 0.32.6 of the btrbk backup utility allow a user who connects via SSH to add extra commands after the expected backup command. This can let an attacker run any command with the rights of the backup account. Upgrade to version 0.32.7 or later, or stop using the provided SSH command filter in authorized_keys, to close the gap.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | digint | btrbk | >= 0.29.0, < 0.32.7 |
| Debian:12 | debian | btrbk | All versions |
| Ubuntu:16.04:LTS | canonical | btrbk | All versions |
Original advisory text
btrbk: SSH Command Filter Bypass in ssh_filter_btrbk.sh
btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_filter_btrbk.sh constructs allow_stream_match with a start anchor but without an end-of-string anchor for the complete command. A user restricted through an authorized_keys forced command can append a trailing pipe command after a valid btrbk command prefix, bypassing the allowlist and executing arbitrary commands with the privileges of the backup-target SSH account. Deployments that do not use ssh_filter_btrbk.sh in authorized_keys are not affected. This issue is fixed in version 0.32.7.
References
- https://github.com/digint/btrbk/security/advisories/GHSA-pf45-7g54-65h5
- https://github.com/digint/btrbk/commit/29ca3c093205395bdeb9dd98677ab4139c458aec
- https://github.com/digint/btrbk/releases/tag/v0.32.7
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62943... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-62943 Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-62943 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-62943 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-62943 Third Party Advisory
Severity
8.7
High
Exploitation
EPSS <1%
Type
CWE-78OS Command Injection
Timeline
Published18 Sep 2026
Updated27 Sep 2026
First seen18 Sep 2026
Sources
CVE-2026-62943 · NVD
CVE-2026-62943 · MITRE
CVE-2026-62943 · OSV
GHSA-pf45-7g54-65h5 · GHSA
DEBIAN-CVE-2026-62943 · OSV
UBUNTU-CVE-2026-62943 · OSV
Track software like this
Free during beta