Code Injection Vulnerability in OpenText Carbonite Safe Server Backup
CVE-2025-9120

8.6HIGH

Key Information:

Vendor
CVE Published:
24 February 2026

What is CVE-2025-9120?

The OpenText Carbonite Safe Server Backup software is susceptible to a Code Injection vulnerability due to improper control of code generation. This critical flaw allows an attacker to exploit open ports, potentially leading to unauthorized access and manipulation of the server. Organizations using Carbonite Safe Server Backup, especially versions up to 6.8.3, must take immediate action to secure their systems and mitigate the risk of exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Carbonite Safe Server Backup 0 <= 6.8.3

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harrison Neal
.