Borgbackup is a deduplicating backup and archiving tool with a niche but strategically important deployment footprint centered on its single Borg product. The durable signal among its disclosures centers on cryptographic signature verification and data-integrity issues, reflecting the trust and authentication demands placed on backup systems that preserve sensitive data. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Borgbackup over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15914HIGH Incorrect implementation of access controls allows remote users to override repository restrictions in Borg servers 1.1.x before 1.1.3. | Feb 8, 2018 | 8.8 | 26 | NO | NO |
CVE-2023-36811MEDIUM borgbackup is an opensource, deduplicating archiver with compression and authenticated encryption. A flaw in the cryptographic authentication scheme in borgbackup allowed an attack | Aug 30, 2023 | 4.7 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Borgbackup.
Media articles that mention a CVE ID that affects a product developed by Borgbackup — matched by CVE ID, not by vendor name.