Junglewise Threat Intelligence

CVE-2026-28199: Veritas NetBackup Flex OS arbitrary file read in management shell

CVE-2026-28199 · Severity: low · CVSS 3.3 · Published 2026-09-18

Vendors: Veritas.

Executive brief

NetBackup Flex OS is an enterprise backup appliance management interface. An authenticated user with shell access can read sensitive files from the system—including configuration data and stored credentials—by crafting a malicious path argument to a diagnostic command. This exposes confidential information that could be leveraged for lateral attacks or further system compromise.

Technical details

This is a path traversal vulnerability in a diagnostic command within the NetBackup Flex OS management shell. An authenticated user with low privilege access can exploit argument injection to supply a specially crafted path that bypasses directory restrictions and reads arbitrary files from the underlying operating system. The attack vector is local/adjacent network with low privilege authentication required; no user interaction is needed. An attacker can disclose sensitive configuration files and credential material stored on the appliance. Patches are available in NetBackup Flex OS version 6.4 and later.

Affected products

  • Veritas NetBackup Flex OS prior to 6.4

Timeline

  • 2026-09-18: disclosed
  • 2026-07-21: advisory: Initial advisory version published

References