Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-77089: Commvault Cloud Command Center API allows unauthorized privilege changes

CVE-2026-77089 · published 1 month ago
Summary

The Command Center API in Commvault Cloud can be accessed without proper authentication, letting attackers modify user privileges. This could let unauthorized users gain elevated rights within the system. Apply the latest maintenance release to fix the issue.

What to do
  • Update commvault commvault cloud to version 11.46.20.
Affected software
VendorProductAffected versions
commvault commvault cloud <= 11.46.19
Fix: upgrade to 11.46.20
commvault commvault >= 11.36.0, < 11.36.123
>= 11.40.0, < 11.40.72
>= 11.44.0, < 11.44.20
>= 11.46.0, < 11.46.20
cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
Original advisory text
Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.
Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-290Authentication Bypass by Spoofing
Timeline
Published8 Sep 2026
Updated11 Oct 2026
First seen8 Sep 2026
Sources
CVE-2026-77089 · MITRE
Track software like this
Free during beta