{"id":"CVE-2026-28197","published":"2026-09-18T12:17:24.573","lastModified":"2026-09-18T19:24:36.593","description":"An authenticated, low-privileged user with access to the NetBackup Flex \nOS management shell could supply a specially crafted input to a \nprivileged administrative command, causing it to execute arbitrary code \nwith root-level permissions. Successful exploitation grants the attacker\n unrestricted control over the Flex appliance host and all hosted \ncontainers, fully compromising confidentiality, integrity, and \navailability.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-88"],"vendors":[],"products":[],"references":[{"url":"https://github.com/cohesity/SecAdvisory/blob/master/COH-2026-0001.md","tags":[]},{"url":"https://www.cvcn.gov.it/cvcn/cve/CVE-2026-28197","tags":[]}],"exploitRefs":[{"url":"https://github.com/cohesity/SecAdvisory/blob/master/COH-2026-0001.md","tags":[]}],"hasPoc":true,"ai":{"summary":"This vulnerability allows a low-privileged user to execute arbitrary code with root permissions by supplying crafted input to a privileged administrative command in NetBackup Flex OS, leading to full control over the appliance and hosted containers.","exploitability":"Exploitation requires access to the NetBackup Flex OS management shell and knowledge of a specific crafted input, making it moderately difficult.","blast_radius":"If exploited, the attacker gains unrestricted control over the Flex appliance host and all hosted containers, fully compromising the system.","remediation":"Disable the affected administrative command or restrict access to the NetBackup Flex OS management shell to low-privileged users.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","auth-bypass","admin-shell"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:24:38.400Z"}}