Description
btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_filter_btrbk.sh constructs allow_stream_match with a start anchor but without an end-of-string anchor for the complete command. A user restricted through an authorized_keys forced command can append a trailing pipe command after a valid btrbk command prefix, bypassing the allowlist and executing arbitrary commands with the privileges of the backup-target SSH account. Deployments that do not use ssh_filter_btrbk.sh in authorized_keys are not affected. This issue is fixed in version 0.32.7.
Published: 2026-09-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Command Execution
Action: Apply Patch
AI Analysis

Impact

A malformed line‑anchor rule in btrbk's ssh_filter_btrbk.sh allows an attacker to bypass the command allowlist and execute arbitrary commands through a forced‑command entry in authorized_keys. The flaw is an instance of OS command injection (CWE‑78) and lets the attacker run any instruction with the SSH account's privileges used for backups, potentially giving full control over the backup target system.

Affected Systems

The vulnerability affects users of Digint btrbk versions 0.29.0 through 0.32.6 that deploy ssh_filter_btrbk.sh as a forced command in authorized_keys. Deployments that do not use the script in authorized_keys, or that are running a later version (0.32.7 or newer), are not impacted.

Risk and Exploitability

With a CVSS score of 8.7 and an EPSS score of < 1%, the risk is considered high. The flaw can be triggered through a normal SSH forced‑command entry, so any attacker who can influence authorized_keys on the backup target can exploit it. The vulnerability is not listed in CISA's KEV catalog, but its severity and vector warrant close attention and timely remediation.

Generated by OpenCVE AI on September 19, 2026 at 16:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade btrbk to version 0.32.7 or later.
  • Remove or disable ssh_filter_btrbk.sh from any authorized_keys forced‑command listings that are not strictly required.
  • If an upgrade cannot be performed immediately, modify the ssh_filter_btrbk.sh script to include an end‑of‑string anchor in the allowlist or otherwise enforce stricter command validation, and restrict the backup‑target SSH account to the minimum necessary privileges.

Generated by OpenCVE AI on September 19, 2026 at 16:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Digint
Digint btrbk
Vendors & Products Digint
Digint btrbk

Fri, 18 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_filter_btrbk.sh constructs allow_stream_match with a start anchor but without an end-of-string anchor for the complete command. A user restricted through an authorized_keys forced command can append a trailing pipe command after a valid btrbk command prefix, bypassing the allowlist and executing arbitrary commands with the privileges of the backup-target SSH account. Deployments that do not use ssh_filter_btrbk.sh in authorized_keys are not affected. This issue is fixed in version 0.32.7.
Title btrbk: SSH Command Filter Bypass in ssh_filter_btrbk.sh
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T20:50:09.611Z

Reserved: 2026-07-14T22:32:17.731Z

Link: CVE-2026-62943

cve-icon Vulnrichment

Updated: 2026-09-18T19:24:37.894Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T17:16:59.167

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-62943

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:00:12Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')