CVE-2026-77089: pre-auth authentication bypass in Commvault Commvault Cloud

An unauthenticated attacker can bypass authentication checks in the Commvault Cloud Command Center API and affect privilege management, allowing privileged actions against the product. This is tracked as CVE-2026-77089 and has a CVSS 3.1 score of 9.8. Affected releases include multiple 11.x maintenance ranges: 11.36.0–11.36.122, 11.40.0–11.40.71, 11.44.0–11.44.19, and 11.46.0–11.46.19; the flaw can be triggered remotely without prior credentials or user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00611
CWE
CWE-290
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as urgent: the issue allows unauthenticated privilege bypass and there is no fixed release listed, so immediately reduce exposure and apply compensating controls while awaiting vendor fixes.

What is CVE-2026-77089?

An unauthenticated attacker can bypass authentication checks in the Commvault Cloud Command Center API and affect privilege management, allowing privileged actions against the product. This is tracked as CVE-2026-77089 and has a CVSS 3.1 score of 9.8. Affected releases include multiple 11.x maintenance ranges: 11.36.0–11.36.122, 11.40.0–11.40.71, 11.44.0–11.44.19, and 11.46.0–11.46.19; the flaw can be triggered remotely without prior credentials or user interaction.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Commvault Commvault Cloud are affected?

BRANCHAFFECTEDFIXED
11.x11.46.0 – 11.46.19
11.x11.44.0 – 11.44.19
11.x11.40.0 – 11.40.71
11.x11.36.0 – 11.36.122

Is CVE-2026-77089 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-77089

  1. Isolate and restrict network access to the Command Center API to trusted management networks only
  2. Implement strict firewall rules and VPN access so the API is not internet-reachable
  3. Enable and monitor detailed authentication and privilege-change logs for the Command Center API
  4. Follow vendor guidance and contact Commvault support for mitigation steps and timelines for a resolved maintenance release

Frequently asked questions

Is CVE-2026-77089 being actively exploited?

There are no public reports of active exploitation of CVE-2026-77089 as of 2026-09-30.

Which Commvault Cloud versions are affected by CVE-2026-77089?

The vulnerability affects multiple Commvault Cloud 11.x maintenance ranges: 11.36.0–11.36.122, 11.40.0–11.40.71, 11.44.0–11.44.19, and 11.46.0–11.46.19.

Is there a patch for CVE-2026-77089?

No fixed versions are listed for CVE-2026-77089; there is no patch available in the provided affected data.

Does CVE-2026-77089 require authentication?

No; the issue is an authentication bypass in the Commvault Cloud Command Center API and can be exploited without valid credentials.

References