CRITICAL 9.3 NVD
CVE-2026-77089
Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update C
Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.
Affected Products
- commvault/commvault
References
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-08 via NVD. Affected: commvault/commvault.
Risk Timeline
CVE Disclosed2026-09-08 · 2 days ago
Remediation Resources
Official Advisory
documentation.commvault.com/securityadvisories/CV_2026_07_1.htmlRelated Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-77097 | Private Metrics Server contained a missing authentication condition affecting me | HIGH | 8.8 |
| CVE-2026-77098 | Private Metrics Server contained an SQL injection condition affecting database o | HIGH | 8.8 |
| CVE-2026-77101 | CommServe contained a stack-based buffer overflow issue affecting service availa | HIGH | 8.7 |
| CVE-2026-77102 | CommServe contained a heap-based buffer overflow issue affecting service availab | HIGH | 8.7 |
| CVE-2026-77103 | CommServe contained an authentication bypass issue affecting access authorizatio | HIGH | 8.7 |
| CVE-2026-77105 | CommServe contained a cryptographic signature verification issue affecting privi | HIGH | 8.7 |
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.