# CVE-2026-53932

## Summary

- **CVE ID:** CVE-2026-53932
- **Severity:** HIGH
- **CVSS Score:** 8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
- **CWE:** CWE-77, CWE-78
- **Published:** Sep 4, 2026
- **Last Modified:** Sep 8, 2026

## Description

laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4.

## Affected Products

- stefanzweifel — laravel-backup-restore (< 1.9.4)

## References

- [CNA](https://github.com/stefanzweifel/laravel-backup-restore/security/advisories/GHSA-w9mx-xmg4-gc4r)
- [CNA](https://github.com/stefanzweifel/laravel-backup-restore/pull/116)
- [CNA](https://github.com/stefanzweifel/laravel-backup-restore/commit/a73f6c3dfd57c5efbc46cce4e93ed033bedce8b0)
- [CNA](https://github.com/stefanzweifel/laravel-backup-restore/releases/tag/v1.9.4)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.91%
- **EPSS Percentile:** 57.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._