shouldiuse.io

VERDICT

Should I use Bareos?

Open-source backup software for Linux, Windows, macOS and more. Enterprise-grade encryption, GDPR-compliant, RBAC, tape/WORM. - bareos.org

Depends. Buy if you run Linux-heavy servers and have a sysadmin to own Director, catalog, and patching — it is deep, free, and compliance-ready. Skip if you want turnkey or point-and-click backup; setup and ongoing administration are real work.

Confidence

Medium. Based on 30+ public sources: vendor pages, docs, Reddit/sysadmin threads, CVE databases, G2, and company profiles.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityPaid subscriptions exist; no user support reviews found
  • Security posture

Pricing

Free

Open Source

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
SubscriptionQuote-based; price list PDF available

Best for

  • Linux-heavy server fleets
  • Compliance-driven orgs (GDPR, NIS2, PCI DSS)
  • Tape and WORM archive shops
  • Teams with dedicated sysadmins

Not for

  • Non-technical teams wanting point-and-click backup
  • Solo users backing up a laptop or two
  • Anyone without admin capacity to run Director and catalog
  • Buyers needing vendor-managed SaaS backup

Gotchas - check before you buy

high

Self-managed security: recurring Director CVEs mean prompt patching is on you

medium

Free core, but plugins and enterprise features are gated behind subscriptions

medium

PostgreSQL catalog and Director tuning required; budget real admin time before go-live

low

Guess: Bacula-to-Bareos migration is mostly compatible but config conversion needs testing

Pros and cons

Pros

  • No license fees; open-source core with optional paid subscriptions
  • GDPR, PCI DSS, SOX and NIS2 compliance support built in
  • Ransomware protection via immutable backups and WORM tape
  • Cross-platform: Linux, Windows, macOS and FreeBSD clients
  • Kubernetes and application-aware container backups

Cons

  • Multiple Director CVEs across years, including high-severity ones
  • Steep setup: Director daemon, PostgreSQL catalog, text configs
  • Tiny vendor (~$880K ARR) behind critical infrastructure
  • Bacula fork — inherits config complexity; users still seek best-practice advice

Sources & method

Analyzed 9/22/2026 - 14 sources - Encryption, RBAC, and GDPR/PCI DSS/SOX/NIS2 compliance claims; recurring Director CVEs from 2020–2024, addressed in releases.

official x6review x4security x2news x2
  • CVE-2022-24756, High-severity issue affecting Bareos Director versions including 21.1.0.
  • CVE-2024-45044, Improper authorization in Bareos; fixed by upgrading.
  • CVE-2020-11061, Stack overflow in Bareos Director, CVSS 7.4, affecting versions below a patched release.
  • CVE-2020-4042, CVSS 6.8 issue where a malicious client could exploit the Director before 19.2.8.

Key stats

  • Value for money: 5/5

    Rating

  • Free

    Starting price

  • 14

    Sources

  • Analyzed

  • Value for money: 5/5. No license fees; open-source core
  • Ease of use: 2/5. Console-first; Director, catalog, text configs
  • Feature depth: 5/5. Tape, WORM, Kubernetes, immutability, compliance
  • Support quality. Paid subscriptions exist; no user support reviews found
  • Security posture: 3/5. Strong features; several patched Director CVEs
  • 4.0/5 G2 rating G2 seller rating
  • €0 License cost No license fees; subscriptions optional
  • Yes Free tier Open-source community edition
  • ~$880K ARR Vendor size Est. $2.6M valuation (GetLatka)

Pricing

Open Source

Free

  • Full backup and recovery core
  • Community support via lists and GitHub
  • Self-managed

Subscription

Quote-based; price list PDF available

  • Vendor support and services
  • Plugins and enterprise features
  • Compliance-oriented offerings

Security

Encryption, RBAC, and GDPR/PCI DSS/SOX/NIS2 compliance claims; recurring Director CVEs from 2020–2024, addressed in releases.

  • CVE-2022-24756High-severity issue affecting Bareos Director versions including 21.1.0.11
  • CVE-2024-45044Improper authorization in Bareos; fixed by upgrading.12
  • CVE-2020-11061Stack overflow in Bareos Director, CVSS 7.4, affecting versions below a patched release.
  • CVE-2020-4042CVSS 6.8 issue where a malicious client could exploit the Director before 19.2.8.

What users say

Sysadmins on Reddit call Bareos a capable, mature choice that does a great job, but threads are full of setup, best-practice, and Bacula-comparison questions.

“BareOS does a great job”
Reddit, r/linuxadmin
“I use bareos personally”
Reddit, r/selfhosted
“I settled on bareos”
Reddit, r/homelab

Alternatives

Compare Bareos with each alternative.

  • Druva

    Vendor-managed SaaS backup if you want zero ops

Companies that use it

  • Webdock
  • Cartika
Full analysis

Based on 30+ public sources: vendor pages, docs, Reddit/sysadmin threads, CVE databases, G2, and company profiles.

Free Bacula-fork backup: deep, compliance-ready, but config-heavy. Great for Linux server fleets with a sysadmin.

Methodology

Based on 30+ public sources: vendor pages, docs, Reddit/sysadmin threads, CVE databases, G2, and company profiles.

Sources

  1. official
  2. official
  3. official
  4. official
  5. official
  6. official
  7. review
  8. review
  9. review
  10. review
  11. security
  12. Snyk — CVE-2024-45044security.snyk.io
    security
  13. news
  14. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.