
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-62268 is a reserved CVE associated with a security vulnerability in BorgBackup (borg), a deduplicating backup program. The vulnerability was addressed in the borgbackup package update to version 1.4.5-52, as noted in Fedora security advisories. The CVE status remains "Reserved" with limited technical details publicly disclosed. Feedly estimates the severity as HIGH, though no official CVSS score has been published (Feedly, OSV).
Technical details for CVE-2026-62268 have not been publicly disclosed as the CVE remains in Reserved status. Based on German-language security coverage referencing "Überschreiben von Dateien" (overwriting of files), the vulnerability appears to involve unauthorized file overwrite capabilities within BorgBackup (Pro-Linux). No CWE classification, attack vector details, or proof-of-concept code have been publicly released at this time.
Based on the available information suggesting a file overwrite vulnerability in BorgBackup, successful exploitation could allow an attacker to overwrite arbitrary files on systems where BorgBackup is used, potentially leading to data corruption, integrity violations, or privilege escalation depending on the files targeted. The exact scope of confidentiality, availability, and integrity impacts remains unclear pending full CVE publication (Feedly, Pro-Linux).
No public proof-of-concept exploit code, in-the-wild exploitation, or threat actor attribution has been reported for CVE-2026-62268. The CVE remains in Reserved status, and no EPSS score or CISA KEV catalog listing has been identified. Detection plugins have been released by Tenable Nessus (plugin IDs 331283, 331671, 331847) and Qualys (detection ID 289202), indicating scanner-level awareness of the vulnerability (Feedly, Tenable).
Users of BorgBackup should update to version 1.4.5-52 or later, which includes the security fix for CVE-2026-62268. Fedora users can apply the update through the standard Fedora package management system (dnf update borgbackup). Monitor official vendor advisories and the CVE publication for additional remediation guidance as technical details become available (LinuxSecurity Fedora 44, LinuxSecurity Fedora 43).
Coverage of CVE-2026-62268 has been limited to Linux security news outlets and package advisory trackers. German security site Pro-Linux published advisories referencing file overwrite risks in BorgBackup, and LinuxCompatible.org reported on the associated Fedora package updates. Community discussion was noted on the Solus Linux forums in the context of weekly update summaries (Pro-Linux, LinuxCompatible, Solus Forums).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."