CVE-2026-28199
An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlying operating system by supplying a specially crafted path argument to a diagnostic command. Successful exploitation could expose sensitive system configuration and credential material stored on the appliance.
- Published Sep 18, 2026
- CVSS 4.8 medium
- 0.1% chance of exploitation in the next 30 days (EPSS)