CVE-2019-4000: Druva Insync

High severity, CVSS 7.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attacker to execute arbitrary Python expressions with root privileges.

Affected products

  • Druva Insync: version 6.5.0 only

Published 2020-02-25. Last modified 2026-06-17.