PatchSiren cyber security CVE debrief
CVE-2026-32999 WebPros CVE debrief
A critical remote code execution vulnerability exists in the Comet Backup server. Insufficient character filtering in the backup agent signing module allows an authenticated tenant administrator to execute arbitrary code with elevated privileges on the affected server and connected devices. The vulnerability was disclosed on May 28, 2026, and carries a CVSS 3.1 score of 9.0 (Critical). The attack vector is network-based, requires high attack complexity, no user interaction, and can result in complete compromise of confidentiality, integrity, and availability across changed scope boundaries. The underlying weakness is categorized as CWE-94 (Improper Control of Generation of Code).
- Vendor
- WebPros
- Product
- Comet Backup
- CVSS
- CRITICAL 9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-28
- Original CVE updated
- 2026-05-29
- Advisory published
- 2026-05-28
- Advisory updated
- 2026-05-29
Who should care
Organizations running Comet Backup server infrastructure, particularly multi-tenant deployments where tenant administrators may have elevated configuration access. Security teams responsible for backup infrastructure, disaster recovery systems, and privileged access management should prioritize assessment and remediation.
Technical summary
The vulnerability stems from insufficient input validation in the backup agent signing module. An authenticated tenant administrator can manipulate branding configuration parameters to inject and execute arbitrary code. The code execution occurs with privileges sufficient to affect both the Comet Backup server and devices connected to it, indicating potential lateral movement or infrastructure-wide compromise. The high attack complexity (AC:H) suggests the exploit may require specific conditions or multiple steps, but the network accessibility and lack of required user interaction maintain significant risk exposure.
Defensive priority
critical
Recommended defensive actions
- Apply vendor-supplied security updates for Comet Backup server as referenced in official advisory
- Restrict tenant administrator privileges to least-privilege principles pending patching
- Audit branding configuration changes for unauthorized modifications
- Monitor for anomalous agent signing activity or unexpected code execution on backup servers and connected devices
- Review network segmentation between backup infrastructure and critical systems given changed-scope CVSS indicator
Evidence notes
Vulnerability disclosed via HackerOne and published in NVD on May 28, 2026. Official vendor advisory confirms RCE via branding configuration. CVSS vector indicates network attack surface with changed scope (S:C), suggesting potential impact beyond the vulnerable component.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-32999 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-32999
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-32999 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-32999
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://support.cometbackup.com/hc/en-us/articles/40655100268439--CVE-2026-32999-RCE-on-Comet-Server-via-branding-configuration
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.