CVE-2025-9120: Opentext Carbonite Safe Server Backup

High severity, CVSS 8.6. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Carbonite Safe Server Backup allows Code Injection.  The vulnerability could be exploited through an open port, potentially allowing unauthorized access. This issue affects Carbonite Safe Server Backup: through 6.8.3.

Affected products

  • Opentext Carbonite Safe Server Backup: up to and including 6.8.3

Published 2026-02-24. Last modified 2026-06-17.