CVE-2023-47102: Urbackup Server

Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.

UrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a username is not valid.

Affected products

  • Urbackup Urbackup Server: version 2.5.31 only

Published 2023-11-07. Last modified 2026-06-17.