What the vulnerability does
01Description
Missing Authorization vulnerability in everestthemes Everest Backup everest-backup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Everest Backup: from n/a through <= 2.3.8.
Explanation of Vulnerability in Simple Terms
02Summary
Everest Backup versions 2.3.8 and earlier lack proper authorization checks, allowing unauthenticated attackers to disrupt the backup service. An attacker can send network requests without credentials to trigger a denial-of-service condition. No authentication or user interaction is required to exploit this vulnerability.
What an attacker can do
03Attacker Capabilities
Disrupt backup operations by sending unauthenticated requests to the service.
Potential impact on your site
04Site Impact
Backup service becomes unavailable, potentially preventing data protection operations.
Conditions required to exploit
05Prerequisites
Network access to the Everest Backup service; no authentication required.
Key dates
06Disclosure timeline
October 27, 2025
CVE published
April 28, 2026
Record updated