Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 28 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution via Unsanitized Signing Module in Comet Backup Server | |
| First Time appeared |
Webpros
Webpros comet Backup |
|
| Vendors & Products |
Webpros
Webpros comet Backup |
Thu, 28 May 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitrary code on behalf of a privileged user on the affected server and connected devices. | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-05-28T13:09:20.180Z
Reserved: 2026-03-17T15:00:07.747Z
Link: CVE-2026-32999
Updated: 2026-05-28T13:09:16.955Z
Status : Deferred
Published: 2026-05-28T05:16:36.107
Modified: 2026-06-17T10:36:43.987
Link: CVE-2026-32999
No data.
OpenCVE Enrichment
Updated: 2026-05-28T05:30:06Z