Comet Backup Server Flaw Exposes Remote Customer Data
ID: 733c3dce-9772-5ac6-9317-ab178bc45f46
STIX ID: report--733c3dce-9772-5ac6-9317-ab178bc45f46
Feed Name: securityonline.info
Threat Score
A critical remote code execution vulnerability (CVE-2026-32999, CVSS 9.1) in Comet Backup allows a tenant administrator to upload signed native modules and run malicious backup-tool clients to achieve full server compromise, access config.cfg and backed-up data, break tenancy boundaries, and execute code on connected endpoints; vendor-hosted instances have been upgraded but self-hosted deployments must immediately update to versions 26.4.3, 26.5.0 or later.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
