CVE-2019-4000: Druva Insync
High severity, CVSS 7.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attacker to execute arbitrary Python expressions with root privileges.
Affected products
- Druva Insync: version 6.5.0 only
Published 2020-02-25. Last modified 2026-06-17.