logo

Comet Backup Server Flaw Exposes Remote Customer Data

ID: 733c3dce-9772-5ac6-9317-ab178bc45f46

STIX ID: report--733c3dce-9772-5ac6-9317-ab178bc45f46

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-31

Date Updated: 2026-05-31

Author: Ddos

...
...

A critical remote code execution vulnerability (CVE-2026-32999, CVSS 9.1) in Comet Backup allows a tenant administrator to upload signed native modules and run malicious backup-tool clients to achieve full server compromise, access config.cfg and backed-up data, break tenancy boundaries, and execute code on connected endpoints; vendor-hosted instances have been upgraded but self-hosted deployments must immediately update to versions 26.4.3, 26.5.0 or later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.