Sceawere
Vulnerability Detail
CVE-2026-108925UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Reflected XSS in Cohesity NetBackup
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.1
- Creation Date
- 3h ago
- Vendor
- Cohesity
- Product
- NetBackup Administration Console web interface
- Attack Type
- CWE-80 Improper neutralization of Script-Related HTML tags in a web page (basic XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Cohesity NetBackup Administration Console web interface. This issue affects NetBackup Administration Console web interface: versions before 11.2. https://github.com/cohesity/SecAdvisory/blob/master/COH-2026-0002.md
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.1",
"pubDate": "2026-10-11T19:16:33.957Z",
"pubdate": "2026-10-11T19:16:33.957Z",
"executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists within the Cohesity NetBackup Administration Console web interface due to the improper neutralization of script-related HTML tags.\nThis vulnerability allows an unauthenticated or authenticated attacker to inject malicious client-side scripts into the web application, which are then rendered within the victim's browser session.\nThe primary impact of this flaw is the potential for session hijacking, unauthorized actions performed on behalf of the administrator, and the exfiltration of sensitive information processed by the administration interface.\nThe vulnerability affects all versions of the NetBackup Administration Console prior to 11.2.\nGiven that the Administration Console handles sensitive infrastructure management, successful exploitation poses a critical risk to the confidentiality and integrity of the backup management environment.\nThe vulnerability originates from a failure to perform adequate input validation and output encoding on user-supplied data, permitting the execution of arbitrary JavaScript within the context of the user's browser.",
"technicalDetails": "The vulnerability is identified as a basic Reflected Cross-Site Scripting (XSS) flaw, stemming from the application's failure to sanitize or encode user-provided input before reflecting it back to the user's web browser. The affected component is the NetBackup Administration Console web interface, specifically where input parameters are processed and displayed within the HTML document structure.\nThe root cause is the improper neutralization of script-related HTML tags. When the application receives a crafted HTTP request containing malicious script payloads, it includes these tags directly in the HTTP response without appropriate contextual encoding. Consequently, the victim's browser interprets the injected tags as executable code rather than plain text.\nThe attack flow commences with the attacker crafting a malicious URI containing the payload within a parameter processed by the Administration Console. The attacker then induces an authenticated administrator or user to click this link. Upon loading the crafted URL, the server processes the request and reflects the malicious script in the generated HTML response. The user's browser, upon receiving the response, executes the injected JavaScript within the security origin of the Administration Console.\nBecause the script executes in the context of the administrator's session, the attacker gains the ability to perform any action authorized for the victim. This includes, but is not limited to, modifying system configurations, accessing sensitive backup data, or capturing administrative session tokens via document.cookie. The exploitation does not require advanced access to the underlying server-side filesystem, as the attack is entirely client-side, targeting the trust relationship between the user's browser and the web interface.\nThe vulnerability affects all iterations of the NetBackup Administration Console prior to version 11.2. The security risk is amplified in environments where administrative users maintain active, privileged sessions in the console while browsing other potentially malicious web resources. By leveraging this vulnerability, an attacker can effectively bypass the intended security controls of the management interface by manipulating the user's client environment to execute unauthorized commands or exfiltrate session data."
}