Cryptographic Bypass in NetBackup Flex OS Management Shell by Vendor Cohesity
CVE-2026-28198

9.4CRITICAL

Key Information:

Vendor

Cohesity

Vendor
CVE Published:
18 September 2026

What is CVE-2026-28198?

An authenticated, low-privileged user can exploit a vulnerability in the NetBackup Flex OS management shell to bypass crucial cryptographic signature verification steps associated with privileged support commands. By providing specially crafted access credentials, the attacker can gain unrestricted root shell access. This poses a significant risk as it compromises the confidentiality, integrity, and availability of the Flex appliance host and all hosted containers, ultimately leading to complete system control.

Affected Version(s)

NetBackup Flex OS 0 < 6.4

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.