CVE-2017-7279: Unitrends Enterprise Backup

Critical severity, CVSS 9.8. EPSS: 4.4% chance of exploitation in the next 30 days.

An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" cookie issued at login.

Affected products

  • Unitrends Enterprise Backup: up to and including 8.2.0-8

Published 2017-04-12. Last modified 2026-06-17.