Junglewise Threat Intelligence

CVE-2026-28197: Cohesity NetBackup Flex OS privilege escalation via argument injection

CVE-2026-28197 · Severity: high · CVSS 8.8 · Published 2026-09-18

Executive brief

NetBackup Flex OS is a backup and recovery appliance used to protect enterprise data. An authenticated low-privileged user with access to the management shell can inject special characters into administrative commands to execute arbitrary code with root-level permissions, granting complete control over the appliance and all hosted containers. This fully compromises the confidentiality, integrity, and availability of all backed-up data and systems.

Technical details

The vulnerability is an argument injection flaw in the NetBackup Flex OS management shell that allows a low-privileged authenticated user to inject shell metacharacters into privileged administrative commands. The vulnerable component is a privileged administrative command that fails to properly sanitize user-supplied input before passing it to shell execution. The attack vector is network-accessible (the management shell is remotely accessible), requires low-privileged authentication, and no user interaction is needed. Successful exploitation results in arbitrary code execution with root privileges, granting complete control over the Flex appliance host and all hosted containers. Upgrades to NetBackup Flex OS 6.4 or later remediate the issue; access restrictions to the management shell provide temporary mitigation but do not eliminate the risk.

Affected products

  • Cohesity NetBackup Flex OS prior to 6.4

Timeline

  • 2026-09-18: disclosed
  • 2026-07-21: other: Advisory revision date

References

Related threats