DIRAS TAKE
Treat this as urgent: the issue allows unauthenticated privilege bypass and there is no fixed release listed, so immediately reduce exposure and apply compensating controls while awaiting vendor fixes.
What is CVE-2026-77089?
An unauthenticated attacker can bypass authentication checks in the Commvault Cloud Command Center API and affect privilege management, allowing privileged actions against the product. This is tracked as CVE-2026-77089 and has a CVSS 3.1 score of 9.8. Affected releases include multiple 11.x maintenance ranges: 11.36.0–11.36.122, 11.40.0–11.40.71, 11.44.0–11.44.19, and 11.46.0–11.46.19; the flaw can be triggered remotely without prior credentials or user interaction.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Commvault Commvault Cloud are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 11.x | 11.46.0 – 11.46.19 | |
| 11.x | 11.44.0 – 11.44.19 | |
| 11.x | 11.40.0 – 11.40.71 | |
| 11.x | 11.36.0 – 11.36.122 |
Is CVE-2026-77089 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-77089
- Isolate and restrict network access to the Command Center API to trusted management networks only
- Implement strict firewall rules and VPN access so the API is not internet-reachable
- Enable and monitor detailed authentication and privilege-change logs for the Command Center API
- Follow vendor guidance and contact Commvault support for mitigation steps and timelines for a resolved maintenance release
Frequently asked questions
Is CVE-2026-77089 being actively exploited?
There are no public reports of active exploitation of CVE-2026-77089 as of 2026-09-30.
Which Commvault Cloud versions are affected by CVE-2026-77089?
The vulnerability affects multiple Commvault Cloud 11.x maintenance ranges: 11.36.0–11.36.122, 11.40.0–11.40.71, 11.44.0–11.44.19, and 11.46.0–11.46.19.
Is there a patch for CVE-2026-77089?
No fixed versions are listed for CVE-2026-77089; there is no patch available in the provided affected data.
Does CVE-2026-77089 require authentication?
No; the issue is an authentication bypass in the Commvault Cloud Command Center API and can be exploited without valid credentials.
References
- nvd.nist.gov/vuln/detail/CVE-2026-77089
- cve.org/CVERecord?id=CVE-2026-77089
- documentation.commvault.com/securityadvisories/CV_2026_07_1.html
- All Commvault CVEs on CVE Radar
- CVEs published in September 2026