Description
An authenticated, low-privileged user with access to the NetBackup Flex
OS management shell could bypass the cryptographic signature
verification step of a privileged support command by supplying a
specially formed access credential. Successful exploitation grants the
attacker an unrestricted root shell with full control over the Flex
appliance host and all hosted containers, completely compromising
confidentiality, integrity, and availability.
Published: 2026-09-18
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via cryptographic signature bypass
Action: Immediate Patch
AI Analysis

Impact

An authenticated low‑privileged user who can access the NetBackup Flex OS management shell can supply a specially crafted access credential that bypasses the cryptographic signature verification of a privileged support command, allowing the attacker to obtain an unrestricted root shell on the Flex appliance host. This grants full control over all hosted containers, directly compromising confidentiality, integrity, and availability.

Affected Systems

The vulnerability affects Cohesity NetBackup Flex OS products accessed through the management shell. No specific version information is listed in the CNA data, so any deployment that provides non‑administrative shell access could be impacted until the vendor addresses the flaw.

Risk and Exploitability

The CVSS score of 9.4 classifies this as a critical vulnerability. EPSS Score is less than 1%, indicating a very low yet non‑zero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog, but the lack of such markers does not reduce the potential for exploitation. The likely attack vector appears to be local or through authorized administrative channels, where an attacker with low privileges can act as a privileged support operator to bypass cryptographic checks and elevate privileges.

Generated by OpenCVE AI on September 19, 2026 at 19:41 UTC.

Remediation

Vendor Workaround

Restrict management shell access to authorized administrators only. No compensating control fully eliminates the risk; upgrading is required.


OpenCVE Recommended Actions

  • Deploy the vendor patch or upgrade to a version that includes the fix for this cryptographic signature verification bypass.
  • Restrict management shell access solely to authorized administrators and block any non‑admin users from using the shell interface.
  • Continuously monitor the Flex appliance host and its containers for abnormal activity or unexpected changes that might indicate an attempted or successful privilege escalation.

Generated by OpenCVE AI on September 19, 2026 at 19:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cohesity
Cohesity netbackup Flex Os
Vendors & Products Cohesity
Cohesity netbackup Flex Os

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Description An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command by supplying a specially formed access credential. Successful exploitation grants the attacker an unrestricted root shell with full control over the Flex appliance host and all hosted containers, completely compromising confidentiality, integrity, and availability.
Title Privilege Escalation via Cryptographic Signature Verification Bypass in NetBackup Flex OS Shell
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Cohesity Netbackup Flex Os
cve-icon MITRE

Status: PUBLISHED

Assigner: ENISA

Published:

Updated: 2026-09-18T14:31:44.992Z

Reserved: 2026-02-25T14:02:29.493Z

Link: CVE-2026-28198

cve-icon Vulnrichment

Updated: 2026-09-18T14:30:11.540Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T12:17:24.717

Modified: 2026-09-18T19:24:36.593

Link: CVE-2026-28198

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:29:46Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature