CVE-2026-104805
Received Received - Intake

Backup Restoration Path Traversal in DigitalCanion

Vulnerability report for CVE-2026-104805, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Switzerland Government Common Vulnerability Program

Description

DigitalCanion has discovered a vulnerability in the backup restoration functionality that allows an attacker with access to the configured backup repository to introduce arbitrary files into the system during restoration. The specific flaw exists within the backup restoration mechanism, which fails to properly validate the paths, file types, integrity, and authenticity of files contained within a restored TGZ archive. The application does not perform file-signature verification before extracting the archive, allowing a specially crafted backup to contain attacker-controlled files. An attacker with access to the backup SFTP or other configured repository can therefore provide a malicious TGZ archive that, when restored by the system, may place arbitrary files on the underlying Linux system. Depending on the location and permissions of the extracted files, this behavior can potentially be leveraged to achieve arbitrary code execution with root privileges and compromise the underlying virtual machine. The absence of enforced backup passwords further reduces the protection provided by the backup mechanism and may facilitate unauthorized access to the repository.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.
CWE-494 The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an attacker with access to the backup repository to inject arbitrary files into the system during backup restoration. The backup restoration mechanism fails to validate file paths, types, integrity, or authenticity in TGZ archives. Without file-signature verification, a malicious backup can place attacker-controlled files on the Linux system, potentially leading to root-level code execution and VM compromise.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized files in backup restoration paths. Inspect TGZ archives before restoration for unexpected files or paths. Monitor system logs for unusual file creation during backup restoration processes.

Impact Analysis

An attacker could exploit this to gain root privileges on the system, compromise the virtual machine, and execute arbitrary code. The lack of backup passwords further increases the risk of unauthorized repository access, enabling attackers to introduce malicious files during restoration.

Mitigation Strategies

Immediately enforce backup passwords and enable file-signature verification for TGZ archives. Restrict access to backup repositories and validate file paths during restoration. Update the backup restoration mechanism to reject archives with invalid file types or paths.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104805. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart