External risk intelligence

NetBackup Flex OS Management Shell Signature Bypass Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-28198

The vulnerability resides within the management shell of a backup appliance. While network-reachable in some environments, such administrative interfaces are typically restricted to internal management networks or accessed via VPN/jump hosts rather than being exposed directly to the public internet.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An authenticated user with limited privileges could bypass security checks on NetBackup Flex OS management commands. This could allow an attacker to gain unrestricted root access, fully compromising the appliance. The main concern is confirming relevance and exposure to our environment.

  • Users can bypass security checks.
  • Unrestricted root access grants full control.
  • Confirm relevance and exposure to our environment.

Attack Path

How an attacker could exploit the issue

An attacker with low-level authenticated access could leverage this vulnerability by interacting with the NetBackup Flex OS management shell. By providing a specially crafted access credential, they can bypass security checks on a privileged command, ultimately leading to full system compromise.

  • Authenticated access required.
  • Bypasses cryptographic signature verification.
  • Grants unrestricted root shell access.

Live Threat

Current exploitation, exposure, and threat context

An authenticated, low-privileged user could potentially gain unrestricted root access to a NetBackup Flex appliance. This could occur by bypassing cryptographic signature verification for a privileged support command, leading to a complete compromise of the appliance's confidentiality, integrity, and availability.

  • Appliance host and containers at risk.
  • Bypassing signature verification.
  • Full control of appliance.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given the nature of this vulnerability impacting an authenticated user with access to the NetBackup Flex OS management shell, ownership likely resides with the Infrastructure or Platform Engineering teams responsible for the appliance's core operating system and its secure configuration. The initial practical move involves identifying all NetBackup Flex appliance instances, confirming their network exposure and business criticality, and then locating the specific system owner to initiate a coordinated remediation plan based on the assessed risk.

  • Infrastructure/Platform teams own remediation.
  • Verify appliance network exposure and criticality.
  • Plan and coordinate vendor-supported fixes.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is NetBackup Flex OS?

NetBackup Flex OS is the underlying platform software for Veritas NetBackup Flex appliances. These systems are enterprise-grade, integrated data protection appliances used to manage, store, and secure massive backups. The software acts as an appliance-level host that runs various containers to manage storage services, data deduplication, and archival tasks within a hardened, centralized infrastructure environment.

What does CWE-347 mean for CVE-2026-28198?

CWE-347 refers to Improper Verification of Cryptographic Signature. In the context of this CVE, it means the system fails to correctly validate the digital "seal" on a privileged command before executing it. Because the appliance does not properly confirm that the command came from a trusted source, an attacker can substitute their own credentials to trick the system into running high-level administrative functions that should normally be blocked.

How does an attacker trigger this vulnerability?

An attacker needs existing, low-privileged access to the NetBackup Flex OS management shell. The vulnerability is triggered by submitting a specifically crafted credential when attempting to execute a restricted support command. This bug is not triggered by standard, authorized administrative tasks or by unauthenticated users, as the system requires that initial, legitimate login to the management interface before the signature check can be bypassed.

Do I need to worry if my appliance is internal?

While the vulnerability technically allows for network-based exploitation, Halo Surface Signal notes that management shells are rarely exposed to the public internet. Most organizations keep these interfaces on isolated management networks or behind VPNs. If your appliance is restricted to internal-only access, your risk is significantly lower than if the management shell is directly reachable from broader network segments.

How should I respond to CVE-2026-28198?

Start by identifying all deployed NetBackup Flex appliance instances within your infrastructure. Coordinate with your platform engineering or infrastructure teams to verify if these management shells are exposed to any untrusted network segments. Once you have a clear inventory, prioritize confirming the ownership of these systems to prepare for applying official vendor patches as soon as they become available.

References