CVE-2026-28197

EUVD-2026-82874
An authenticated, low-privileged user with access to the NetBackup Flex 
OS management shell could supply a specially crafted input to a 
privileged administrative command, causing it to execute arbitrary code 
with root-level permissions. Successful exploitation grants the attacker
 unrestricted control over the Flex appliance host and all hosted 
containers, fully compromising confidentiality, integrity, and 
availability.
Argument Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H