Vulnerability Intelligence Report
Command Center API Authentication Bypass
CVE-2026-77089
Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.
No Active Exploit Signals
CVSS Base Score
9.3
CRITICAL
EPSS Probability:0.33%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-290 ↗CWE-290: Authentication Bypass by Spoofing
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Commvault | Commvault Cloud | 11.46.0 <= 11.46.19 (affected), 11.44.0 <= 11.44.19 (affected), 11.40.0 <= 11.40.71 (affected), 11.36.0 <= 11.36.122 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.330%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Commvault Systems Inc. · Vendor · USA |
| Reserved | 2026-08-20T10:56:18 |
| Published | 2026-09-08T12:12:53 |
| Last Updated | 2026-09-09T12:34:01 |
Community Chatter & Buzz