← Vulnerability feed

Vulnerability record · CVE-2018-6328 · published 14 March 2018

CVE-2018-6328: Unitrends Backup authentication bypass leads to command injection

Kaseya · Unitrends Backup

Unitrends Backup before 10.1.0 exposes a user interface vulnerable to an authentication bypass, allowing an unauthenticated user to reach the /api/hosts endpoint. Because the parameters there are passed to a shell without sanitization, backquotes can be used to inject arbitrary commands. This is a critical pre-auth remote code execution flaw in a backup product that typically holds privileged credentials and access to protected data.

9.8 CVSS 3.0 Critical EPSS 64% · top 0.8% CWE-287 · Improper authentication
9.8CVSS 3.0 base score, v2 7.5
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into its /api/hosts parameters using backquotes.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityPre-authentication remote command execution with a CVSS score of 9.8, public exploit code and very high EPSS probability makes this an urgent patch target.

What it is

Unitrends Backup before 10.1.0 exposes a user interface vulnerable to an authentication bypass, allowing an unauthenticated user to reach the /api/hosts endpoint. Because the parameters there are passed to a shell without sanitization, backquotes can be used to inject arbitrary commands. This is a critical pre-auth remote code execution flaw in a backup product that typically holds privileged credentials and access to protected data.

Impact

An unauthenticated attacker can execute arbitrary commands on the backup server, likely with the privileges of the web service, leading to full compromise of the host and any data or credentials it manages.

Attack surface

Reachable over the network via the Unitrends Backup web interface and its /api/hosts API; the CVSS vector shows no privileges or user interaction required. No authentication is needed because the flaw is itself an authentication bypass.

Exploitation

Not listed in CISA KEV, but public exploit code exists in Exploit-DB (44297, 45559) and EPSS is high at 0.64 (99th percentile), indicating elevated likelihood of exploitation.

What to do

  • Upgrade Unitrends Backup to 10.1.0 or later as directed by the vendor advisories.
  • If immediate patching is not possible, restrict network access to the Unitrends Backup web interface and API to trusted management networks only.
  • Place the appliance behind a firewall or VPN and block direct internet exposure of the UI and /api endpoints.
  • Monitor and rotate any credentials or secrets stored on or accessible from the backup server, since command execution may expose them.
  • Review vendor advisories 000001150 and 000006002 for any additional hardening guidance.

Detection

  • Inspect web and API logs for requests to /api/hosts containing backquotes or shell metacharacters.
  • Alert on unexpected child processes spawned by the Unitrends web service (for example shells or command interpreters).
  • Monitor for anomalous outbound connections or new listening services on the backup server.
  • Audit authentication logs for access to the UI or API without a valid session preceding command activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-6328 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-40386Kaseya unitrends backup vulnerabilityKaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code.EPSS 1.9%9.8CVE-2021-43033Kaseya unitrends backup os command injection vulnerabilityAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary r…EPSS 6.0%9.8CVE-2021-43035Kaseya unitrends backup sql injection vulnerabilityAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowi…EPSS 3.3%9.8CVE-2021-43036Kaseya unitrends backup weak password requirements vulnerabilityAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak.EPSS 1.9%9.8CVE-2021-43042Kaseya unitrends backup classic buffer overflow vulnerabilityAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer component. This was exploita…EPSS 2.9%9.8CVE-2021-43044Kaseya unitrends backup hard-coded credentials vulnerabilityAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community.EPSS 1.9%9.8CVE-2017-12477Unitrends Backup bpserverd authentication bypass allows root command executionThe bpserverd proprietary protocol in Unitrends Backup before 10.0.0, invoked through xinetd, can have its authentication bypassed. A remote attacker…EPSS 68%analysed9.8CVE-2017-12478Unitrends Backup api/storage auth bypass leads to root command executionThe api/storage web interface in Unitrends Backup before 10.0.0 fails to validate an input parameter, allowing authentication to be bypassed. Because…EPSS 78%analysed

Source: NIST National Vulnerability Database (record CVE-2018-6328), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.