Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-77089: Commvault Cloud Command Center API allows unauthorized privilege changes
CVE-2026-77089 · published 1 month ago
Summary
The Command Center API in Commvault Cloud can be accessed without proper authentication, letting attackers modify user privileges. This could let unauthorized users gain elevated rights within the system. Apply the latest maintenance release to fix the issue.
What to do
- Update commvault commvault cloud to version 11.46.20.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| commvault | commvault cloud |
<= 11.46.19 Fix: upgrade to 11.46.20
|
| commvault | commvault |
>= 11.36.0, < 11.36.123 >= 11.40.0, < 11.40.72 >= 11.44.0, < 11.44.20 >= 11.46.0, < 11.46.20 cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:* |
Original advisory text
Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.
Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.
References
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.3
Critical
Type
CWE-290Authentication Bypass by Spoofing
Timeline
Published8 Sep 2026
Updated11 Oct 2026
First seen8 Sep 2026
Track software like this
Free during beta