OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-104805

HIGH · CVSS 8.5 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability in the backup restoration functionality of Linux systems allows an attacker with access to the backup repository to introduce arbitrary files during restoration, due to inadequate validation of file paths and types in TGZ archives. This flaw can lead to arbitrary code execution with root privileges, compromising the underlying virtual machine. Organizations using Linux with backup capabilities should prioritize addressing this vulnerability to safeguard against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104805
Severity
HIGH
CVSS
8.5
EPSS
0.22%
Linux

Original NVD Description

DigitalCanion has discovered a vulnerability in the backup restoration functionality that allows an attacker with access to the configured backup repository to introduce arbitrary files into the system during restoration. The specific flaw exists within the backup restoration mechanism, which fails to properly validate the paths, file types, integrity, and authenticity of files contained within a restored TGZ archive. The application does not perform file-signature verification before extracting the archive, allowing a specially crafted backup to contain attacker-controlled files. An attacker with access to the backup SFTP or other configured repository can therefore provide a malicious TGZ archive that, when restored by the system, may place arbitrary files on the underlying Linux system. Depending on the location and permissions of the extracted files, this behavior can potentially be leveraged to achieve arbitrary code execution with root privileges and compromise the underlying virtual machine. The absence of enforced backup passwords further reduces the protection provided by the backup mechanism and may facilitate unauthorized access to the repository.