PT-2026-83878 · Unknown · Keep Backup Daily

·

CVE-2026-75133

·

Published

2026-08-31

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Keep Backup Daily versions prior to 2.1.4
Description An issue allows unauthenticated attackers to trigger a full MySQL database dump by accessing the publicly exposed kbd cron process parameter. Attackers can download the generated backup from the publicly accessible uploads directory by predicting the filename, which is based on the database name, a limited random range, and the current Unix timestamp.
Recommendations Update to version 2.1.4 or later.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75133

Affected Products

Keep Backup Daily