Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitrary code on behalf of a privileged user on the affected server and connected devices.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 28 May 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution via Unsanitized Signing Module in Comet Backup Server | |
| First Time appeared |
Webpros
Webpros comet Backup |
|
| Vendors & Products |
Webpros
Webpros comet Backup |
Thu, 28 May 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitrary code on behalf of a privileged user on the affected server and connected devices. | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-05-28T04:01:38.421Z
Reserved: 2026-03-17T15:00:07.747Z
Link: CVE-2026-32999
No data.
Status : Received
Published: 2026-05-28T05:16:36.107
Modified: 2026-05-28T05:16:36.107
Link: CVE-2026-32999
No data.
OpenCVE Enrichment
Updated: 2026-05-28T05:30:06Z
Weaknesses