A vulnerability classified as critical has been found in Runtipi up to 4.6.x. This affects an unknown part of the component BackupManager. The manipulation leads to os command injection.

This vulnerability is traded as CVE-2026-24129. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.