CVE-2026-28199

Summary

An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlying operating system by supplying a specially crafted path argument to a diagnostic command. Successful exploitation could expose sensitive system configuration and credential material stored on the appliance.

Affected Software

VendorProductVersion RangeStatus
CohesityNetBackup Flex OS0 < 6.4affected

Weaknesses

  • CWE-347: CWE-347 Improper verification of cryptographic signature

Workarounds

Restrict management shell access to authorized administrators only. No compensating control fully eliminates the risk; upgrading is required.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References