CVE-2026-77089
published 2026-09-08CVE-2026-77089: Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update…
PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.33%
26.2th percentile
Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| commvault | commvault | >= 11.36.0 < 11.36.123 | 11.36.123 |
| commvault | commvault | >= 11.40.0 < 11.40.72 | 11.40.72 |
| commvault | commvault | >= 11.44.0 < 11.44.20 | 11.44.20 |
| commvault | commvault | >= 11.46.0 < 11.46.20 | 11.46.20 |
| commvault | commvault_cloud | 11.36.0 – 11.36.122 | — |
| commvault | commvault_cloud | 11.40.0 – 11.40.71 | — |
| commvault | commvault_cloud | 11.44.0 – 11.44.19 | — |
| commvault | commvault_cloud | 11.46.0 – 11.46.19 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Commvault Command Center up to 11.36.122/11.40.71/11.44.19/11.46.19 authentication spoofing
vuldb·2026-09-13·CVSS 9.8
CVE-2026-77089 [CRITICAL] Commvault Command Center up to 11.36.122/11.40.71/11.44.19/11.46.19 authentication spoofing
A vulnerability was found in Commvault Command Center up to 11.36.122/11.40.71/11.44.19/11.46.19. It has been declared as critical. This impacts an unknown function. The manipulation results in authentication bypass by spoofing.
This vulnerability is cataloged as CVE-2026-77089. The attack may be launched remotely. There is no exploit available.
GHSA
Command Center API contained an authentication bypass issue affecting privilege management.
ghsa_unreviewed·2026-09-08
CVE-2026-77089 [CRITICAL] CWE-290 Command Center API contained an authentication bypass issue affecting privilege management.
Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-08
Published