{"id":"CVE-2026-28199","title":"An authenticated user with access to the NetBackup Flex OS management \nshell could read arbitrary files from the underlying operating system by\n supplying a specially crafted path argument to a diagnostic command","summary":"An authenticated user with access to the NetBackup Flex OS management \nshell could read arbitrary files from the underlying operating system by\n supplying a specially crafted path argument to a diagnostic command. \nSuccessful exploitatio…","severity":"low","cvss":3.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-347"],"vendor":"Cohesity","product":"NetBackup Flex OS","affected":["netbackup_flex_os < 6.4"],"published":"2026-09-18","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:24:36.593","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-28199","references":[{"url":"https://github.com/cohesity/SecAdvisory/blob/master/COH-2026-0001.md","label":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"},{"url":"https://www.cvcn.gov.it/cvcn/cve/CVE-2026-28199","label":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-18T14:14:05.944780Z"},"ingestedAt":"2026-09-18T11:40:03.683Z","epss":0.00075,"epssPercentile":0.001,"slug":"CVE-2026-28199","body":"## Overview\n\nAn authenticated user with access to the NetBackup Flex OS management \nshell could read arbitrary files from the underlying operating system by\n supplying a specially crafted path argument to a diagnostic command. \nSuccessful exploitation could expose sensitive system configuration and \ncredential material stored on the appliance.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":18,"depthScoreParts":{"impact":18.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}