A AegiFlow
MEDIUMCVSS 4.8

CVE-2026-28199

CVE-2026-28199 updated by NVD

Published
2026-09-18
Modified
2026-09-20
Sources
euvd, nvd

Summary

An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlying operating system by supplying a specially crafted path argument to a diagnostic command. Successful exploitation could expose sensitive system configuration and credential material stored on the appliance.

References

Includes data from the ENISA EU Vulnerability Database (EUVD).

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.