CVE-2026-28198

EUVD-2026-82875
An authenticated, low-privileged user with access to the NetBackup Flex 
OS management shell could bypass the cryptographic signature 
verification step of a privileged support command by supplying a 
specially formed access credential. Successful exploitation grants the 
attacker an unrestricted root shell with full control over the Flex 
appliance host and all hosted containers, completely compromising 
confidentiality, integrity, and availability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H