Authenticated OS Command Injection Vulnerability in Cohesity TranZman Web Application
CVE-2025-67840

7.2HIGH

Key Information:

Vendor

Cohesity

Status
Vendor
CVE Published:
3 March 2026

What is CVE-2025-67840?

Multiple OS command injection vulnerabilities exist in the TranZman web application API endpoints, particularly affecting authenticated admin users. By directly concatenating user inputs into system commands without proper sanitization, attackers can leverage these flaws to inject and execute arbitrary commands with root access. This can be exploited through legitimate API requests during processes like job creation or execution. An attacker can modify parameters to include shell metacharacters, enabling remote code execution and bypassing the CLISH restricted shell. As a result, the system can be fully compromised, affecting the security and integrity of the appliance. The vulnerabilities persist even in the latest patched version (TZM_1757588060_SEP2025_FULL.depot).

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.