CVE-2025-67840 Details
Description
Multiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4.0 Build 14614 through TZM_1757588060_SEP2025_FULL.depot web application API endpoints (including Scheduler and Actions pages). The appliance directly concatenates user-controlled parameters into system commands without sufficient sanitisation, allowing an authenticated admin user to inject and execute arbitrary OS commands with root privileges. An attacker can intercept legitimate requests (e.g. during job creation or execution) using a proxy and modify parameters to include shell metacharacters, achieving remote code execution on the appliance. This completely bypasses the intended CLISH restricted shell confinement and results in full system compromise. The vulnerabilities persist in Release 4.0 Build 14614 including the latest patch (as of the time of testing) TZM_1757588060_SEP2025_FULL.depot.
A high-severity OS command injection vulnerability has been identified in the Cohesity TranZman Migration Appliance, specifically in Release 4.0 Build 14614, including the latest patch as of testing. This vulnerability exists within the web application API endpoints, particularly the Scheduler and Actions pages. The issue arises because the application directly concatenates user-controlled input into system commands without adequate sanitization. As a result, an authenticated admin user can inject and execute arbitrary OS commands with root privileges. Exploitation can be achieved by intercepting and modifying legitimate requests to include shell metacharacters, thereby executing commands on the appliance. This exploitation bypasses the intended CLISH restricted shell confinement, leading to a complete system compromise.
Cohesity has released patches for this vulnerability. Users should apply the patches in the following order: `TZM_patch_1.patch` followed by `TZM_1760106063_OCT2025R2_FULL.depot`. For the latest OVA version with integrated fixes, contact Cohesity support.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cohesity.com | [email protected] | Product |
| https://gist.github.com/GregDurys/ef7fc6a36646df927374bba8e7279270 | [email protected] | ExploitThird Party Advisory |
| https://github.com/GregDurys/Cohesity-TranZman-CVEs | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| cohesity tranzman | 4.0 build14614 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 5, 2026 | Initial Analysis | [email protected] |
| Mar 3, 2026 | CVE Modified | CISA-ADP |
| Mar 3, 2026 | New CVE Received | [email protected] |