Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-28197: NetBackup Flex OS lets low‑level user gain admin control

CVE-2026-28197 · published 3 days ago
Summary

A user with limited rights on the NetBackup Flex OS management console can enter specially crafted input that tricks a privileged command into running with full system rights. This can give the attacker complete control over the appliance and any containers it hosts, risking data loss and service disruption. Apply the vendor’s update or restrict access to the management shell until a fix is installed.

What to do
  • Update cohesity netbackup flex os to version 6.4 or later.
Affected software
VendorProductAffected versions
cohesity netbackup flex os < 6.4
Original advisory text
Privilege Escalation via Argument Injection in NetBackup Flex OS Shell
An authenticated, low-privileged user with access to the NetBackup Flex
OS management shell could supply a specially crafted input to a
privileged administrative command, causing it to execute arbitrary code
with root-level permissions. Successful exploitation grants the attacker
unrestricted control over the Flex appliance host and all hosted
containers, fully compromising confidentiality, integrity, and
availability.
Severity
9.4 Critical
CVSS 3.1: 8.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Timeline
Published18 Sep 2026
Updated21 Sep 2026
First seen18 Sep 2026
Sources
CVE-2026-28197 · MITRE
Track software like this
Free during beta