Executive brief
NetBackup Flex OS is a backup and data management appliance used in enterprise environments. An authenticated user with basic shell access can bypass security controls and gain unrestricted root-level access to the entire appliance and all running containers. This compromise allows an attacker to read, modify, or delete any data, disrupt backup operations, and pivot to other connected systems.
Technical details
The vulnerability is a cryptographic signature verification bypass in the Flex OS management shell's privileged support command handler. An authenticated, low-privileged user can supply a specially crafted access credential to skip the signature validation step, allowing arbitrary command execution with root privileges. Attack preconditions require prior authentication and shell access; however, no user interaction is needed once authenticated. Successful exploitation grants unrestricted root shell access over the Flex host and all hosted containers. Patches are available in NetBackup Flex OS 6.4 and later versions.
Affected products
- Cohesity NetBackup Flex OS prior to 6.4
Timeline
- 2026-09-18: disclosed
- 2026-07-21: advisory: Initial advisory revision published