Executive brief
A vulnerability in Comet Backup Server allows a tenant administrator to execute unauthorized commands on the central backup server and all connected devices. Comet Backup is a platform used by service providers to manage data backups for multiple clients. An exploit could lead to a total compromise of the backup infrastructure, allowing an attacker to access sensitive customer data or disrupt recovery operations across the entire network.
Technical details
A code injection vulnerability (CWE-94) exists in the backup agent signing module of Comet Backup Server due to insufficient character filtering. An authenticated tenant administrator can exploit this flaw via branding configuration settings to execute arbitrary code on the server. Because the server manages connected backup agents, the execution context allows the attacker to extend their reach to connected devices. The attack requires network access to the server's management interface and valid tenant administrator credentials. While the CVSS vector provided by the CNA suggests no prerequisites, the description clarifies that the attacker must be an authenticated tenant administrator.
Affected products
- Comet Backup Comet Backup Server
Timeline
- 2026-05-28: disclosed: Initial disclosure via NVD and HackerOne