{"id":"CVE-2026-28197","title":"An authenticated, low-privileged user with access to the NetBackup Flex \nOS management shell could supply a specially crafted input to a \nprivileged administrative command, causing it to execute arbitrary code \nwith root-level permission…","summary":"An authenticated, low-privileged user with access to the NetBackup Flex \nOS management shell could supply a specially crafted input to a \nprivileged administrative command, causing it to execute arbitrary code \nwith root-level permission…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-88"],"vendor":"Cohesity","product":"NetBackup Flex OS","affected":["netbackup_flex_os < 6.4"],"published":"2026-09-18","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:24:36.593","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-28197","references":[{"url":"https://github.com/cohesity/SecAdvisory/blob/master/COH-2026-0001.md","label":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"},{"url":"https://www.cvcn.gov.it/cvcn/cve/CVE-2026-28197","label":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-18T14:14:31.135668Z"},"ingestedAt":"2026-09-18T11:40:03.686Z","epss":0.0037,"epssPercentile":0.30929,"slug":"CVE-2026-28197","body":"## Overview\n\nAn authenticated, low-privileged user with access to the NetBackup Flex \nOS management shell could supply a specially crafted input to a \nprivileged administrative command, causing it to execute arbitrary code \nwith root-level permissions. Successful exploitation grants the attacker\n unrestricted control over the Flex appliance host and all hosted \ncontainers, fully compromising confidentiality, integrity, and \navailability.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}