CVE-2026-28198

8.8

Cohesity · NetBackup Flex OS

A cryptographic signature bypass in the Cohesity NetBackup Flex OS management shell allows authenticated, low-privileged users to execute privileged commands and gain root access to the appliance.

Executive summary

A critical vulnerability in Cohesity NetBackup Flex OS allows authenticated users to escalate privileges to root, resulting in a total compromise of the appliance.

Vulnerability

The flaw, classified as CWE-347, involves the improper verification of cryptographic signatures within the management shell. By supplying specially formed access credentials, an authenticated, low-privileged user can bypass signature checks to execute privileged support commands, resulting in full root access to the host.

Business impact

Successful exploitation leads to a complete loss of confidentiality, integrity, and availability for the affected appliance and all hosted containers. With a CVSS score of 8.8, this vulnerability poses a severe risk, as it grants attackers unrestricted control over critical backup infrastructure, potentially allowing for the deletion or exfiltration of sensitive organizational data.

Remediation

Immediate Action: Update Cohesity NetBackup Flex OS to version 6.4 or later to resolve the underlying cryptographic verification failure.

Proactive Monitoring: Audit management shell access logs for unusual or unauthorized command executions, particularly those originating from accounts with low-level privileges.

Compensating Controls: Restrict access to the management shell to authorized personnel only and ensure the appliance is isolated within a secure management network segment to limit the attack surface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for total system compromise, organizations should prioritize patching their Cohesity NetBackup Flex OS deployments immediately. Testing and deploying version 6.4 will eliminate the root cause of this privilege escalation, ensuring the integrity of the backup management environment.

More Cohesity CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources