Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an export must have been previously requested by someone with the "Synchronize, import, and export configuration" permission. NOTE: CVE-2026-107914 refers to the vulnerability in which config.admin.inc does not ensure that a file_unmanaged_delete operation occurs. Therefore, many archives could persist: config.tar.gz, config_0.tar.gz, config_1.tar.gz, etc. There is a separate config.module issue that could allow remote access by an anonymous user, but only for the one filename config.tar.gz.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-107914 affects Backdrop CMS versions 1.34 before 1.34.5 and 1.35 before 1.35.1, exposing a critical flaw in configuration export handling. The vulnerability stems from insufficient protection of compressed configuration archives and, more critically, the failure of config.admin.inc to properly execute file_unmanaged_delete operations. This means exported configuration archives—which may contain sensitive database credentials, API keys, and system settings—can persist on the server long after export operations complete. While the vulnerability requires an attacker to have "Synchronize, import, and export configuration" permissions, a compromised administrative account or insider threat could exploit this to exfiltrate sensitive configurations that remain accessible via predictable file paths or directory traversal techniques.
Although CVE-2026-107914 is not currently mapped to specific MITRE ATT&CK techniques, practitioners using Casky's AI-driven threat detection would identify attack patterns consistent with T1005 (Data from Local System) and T1041 (Exfiltration Over C2 Channel). The platform's 754 security skills—powered by Claude's extended reasoning capabilities—would flag suspicious configuration export activities by detecting: (1) repeated or automated export requests from administrative accounts, (2) failure to delete temporary archive files within expected timeframes, (3) archive files accessed from unexpected network locations, and (4) configuration files containing plaintext credentials being staged for transmission. Security practitioners would see findings highlighting the persistence of undeleted archives as a post-exploitation indicator and receive guidance on validating that file deletion operations complete successfully during the export process.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-107914. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation