CVE-2026-44926

8.8

Veritas · InfoScale CmdServer

A security vulnerability exists in Veritas InfoScale CmdServer versions prior to 7, which may lead to unauthorized system access.

Executive summary

A critical security vulnerability in Veritas InfoScale CmdServer versions prior to 7 poses a high risk of unauthorized access and system compromise.

Vulnerability

This vulnerability affects the CmdServer component of InfoScale. The CVSS vector (PR:L) indicates that an authenticated user with low privileges can achieve high levels of impact across confidentiality, integrity, and availability.

Business impact

The CVSS score of 8.8 reflects the high severity of this flaw, which allows for the compromise of critical enterprise data and system services. Unauthorized access at this level could lead to a complete takeover of the InfoScale management layer, causing significant operational downtime and potential data loss.

Remediation

Immediate Action: Upgrade Veritas InfoScale CmdServer to version 7 or higher as specified in the official vendor security bulletin.

Proactive Monitoring: Review InfoScale CmdServer access and audit logs for suspicious activity or unauthorized commands executed by low-privileged user accounts.

Compensating Controls: Restrict network access to the CmdServer management interface to known, trusted management workstations via firewall rules or VPNs.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Veritas InfoScale is a core infrastructure component; therefore, patching this vulnerability is critical to maintaining organizational security. Organizations should verify their current version and schedule an upgrade to version 7 immediately to eliminate the exposure.

More Veritas CVEs