PT-2026-44177 · Webpros · Comet Backup

Published

2026-05-28

·

Updated

2026-05-28

·

CVE-2026-32999

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitrary code on behalf of a privileged user on the affected server and connected devices.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-32999

Affected Products

Comet Backup