Arbitrary File Reading Vulnerability in NetBackup Flex OS by Cohesity
CVE-2026-28199

4.8MEDIUM

Key Information:

Vendor

Cohesity

Vendor
CVE Published:
18 September 2026

What is CVE-2026-28199?

An authenticated user with access to the NetBackup Flex OS management shell can exploit an arbitrary file reading vulnerability. By supplying a specially crafted path argument to a diagnostic command, the user may gain access to sensitive files on the underlying operating system. This could lead to the exposure of critical system configurations and credentials stored on the appliance, posing significant security risks to the affected systems.

Affected Version(s)

NetBackup Flex OS 0 < 6.4

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Francesco Caserta (ACN)
.