{"id":"CVE-2026-28198","published":"2026-09-18T12:17:24.717","lastModified":"2026-09-18T19:24:36.593","description":"An authenticated, low-privileged user with access to the NetBackup Flex \nOS management shell could bypass the cryptographic signature \nverification step of a privileged support command by supplying a \nspecially formed access credential. Successful exploitation grants the \nattacker an unrestricted root shell with full control over the Flex \nappliance host and all hosted containers, completely compromising \nconfidentiality, integrity, and availability.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-347"],"vendors":[],"products":[],"references":[{"url":"https://github.com/cohesity/SecAdvisory/blob/master/COH-2026-0001.md","tags":[]},{"url":"https://www.cvcn.gov.it/cvcn/cve/CVE-2026-28198","tags":[]}],"exploitRefs":[{"url":"https://github.com/cohesity/SecAdvisory/blob/master/COH-2026-0001.md","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows a low-privileged user to bypass cryptographic signature verification, gaining unrestricted root access. This is a severe risk as it can fully compromise the system.","exploitability":"Exploitation requires access to the NetBackup Flex OS management shell and knowledge of a specially formed access credential. It is moderately hard to exploit.","blast_radius":"If exploited, the attacker gains full control over the Flex appliance host and hosted containers, compromising confidentiality, integrity, and availability.","remediation":"Disable the affected feature or restrict access to the NetBackup Flex OS management shell.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","auth-bypass","os-shell","netbackup"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:24:27.195Z"}}