Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-28198: NetBackup Flex OS lets low‑privilege user gain full control

CVE-2026-28198 · published 3 days ago
Summary

A user who can log into the NetBackup Flex OS management console can trick the system into skipping a security check and run a support command with full administrator rights. This gives the user complete control over the appliance and any containers it runs, putting all data at risk. Apply the latest vendor patch or update the system to close the bypass.

What to do
  • Update cohesity netbackup flex os to version 6.4 or later.
Affected software
VendorProductAffected versions
cohesity netbackup flex os < 6.4
Original advisory text
Privilege Escalation via Cryptographic Signature Verification Bypass in NetBackup Flex OS Shell
An authenticated, low-privileged user with access to the NetBackup Flex
OS management shell could bypass the cryptographic signature
verification step of a privileged support command by supplying a
specially formed access credential. Successful exploitation grants the
attacker an unrestricted root shell with full control over the Flex
appliance host and all hosted containers, completely compromising
confidentiality, integrity, and availability.
Severity
9.4 Critical
CVSS 3.1: 8.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-347Improper Verification of Cryptographic Signature
Timeline
Published18 Sep 2026
Updated20 Sep 2026
First seen18 Sep 2026
Sources
CVE-2026-28198 · MITRE
Track software like this
Free during beta