Cryptographic Bypass in NetBackup Flex OS Management Shell by Vendor Cohesity
CVE-2026-28198
9.4CRITICAL
What is CVE-2026-28198?
An authenticated, low-privileged user can exploit a vulnerability in the NetBackup Flex OS management shell to bypass crucial cryptographic signature verification steps associated with privileged support commands. By providing specially crafted access credentials, the attacker can gain unrestricted root shell access. This poses a significant risk as it compromises the confidentiality, integrity, and availability of the Flex appliance host and all hosted containers, ultimately leading to complete system control.
Affected Version(s)
NetBackup Flex OS 0 < 6.4
