CWE-530: Exposure of Backup File to an Unauthorized Control Sphere
A backup file is stored in a directory or archive that is made accessible to unauthorized actors.
Last updated
Overview
Often, older backup files are renamed with an extension such as .~bk to distinguish them from production files. The source code for old files that have been renamed in this manner and left in the webroot can often be retrieved. This renaming may have been performed automatically by the web server, or manually by the administrator.
Real-world CVEs
10 recorded CVEs are caused by CWE-530 (Exposure of Backup File to an Unauthorized Control Sphere). The highest-severity and most recent are shown first. 1 new CWE-530 CVE has been recorded so far in 2026 (3 in 2025).
- CVE-2020-36899
QiHang Media Web Digital Signage 3.0.9 Unauthenticated Arbitrary File Disclosure
High · CVSS 8.72025-12-10 - CVE-2024-12330
WP Database Backup – Unlimited Database & Files Backup by Backup for WP <= 7.3 - Unauthenticated Database Back-Up Exposure
High · CVSS 7.52025-01-09 - CVE-2024-56462
IBM QRadar SIEM is vulnerable to using components with known vulnerabilities