Bacula is a modestly represented backup and recovery platform whose vulnerability footprint, despite limited product breadth, reflects the security exposure inherent in systems that handle sensitive data in transit and at rest. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, with the recurring exposure centered on SQL injection, cleartext transmission of credentials and backup content, and link-following issues that characterize file-handling and database-driven backup software. Defenders should prioritize patching of internet-exposed Bacula directors and storage daemons, and audit backup workflows for credential exposure; live severity and exploitation details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bacula over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15367CRITICAL Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escala | Mar 7, 2018 | 9.8 | 56 | NO | YES |
CVE-2014-8295HIGH SQL injection vulnerability in joblogs.php in Bacula-Web 5.2.10 allows remote attackers to execute arbitrary SQL commands via the jobid parameter. | Oct 15, 2014 | 7.5 | 28 | NO | YES |
CVE-2025-45346HIGH SQL Injection vulnerability in Bacula-web before v.9.7.1 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request. | Jul 29, 2025 | 8.1 | 26 | NO | NO |
CVE-2008-5373MEDIUM mtx-changer.Adic-Scalar-24 in bacula-common 2.4.2 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/mtx.##### temporary file, probably a related issue | Dec 8, 2008 | 6.9 | 22 | NO | NO |
CVE-2012-4430MEDIUM The dump_resource function in dird/dird_conf.c in Bacula before 5.2.11 does not properly enforce ACL rules, which allows remote authenticated users to obtain resource dump informat | Oct 10, 2012 | 4.0 | 17 | NO | NO |
CVE-2007-5626MEDIUM make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mail containing this command line, | Oct 23, 2007 | 5.5 | 16 | NO | NO |
bacula 1.36.3 and earlier allows local users to modify or read sensitive files via symlink attacks on (1) the temporary file used by autoconf/randpass when openssl is not available | Sep 20, 2005 | 3.6 | 13 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bacula.
Media articles that mention a CVE ID that affects a product developed by Bacula — matched by CVE ID, not by vendor name.