Executive brief
Commvault Command Center is a web-based interface used to manage backup and recovery operations across an organization's IT infrastructure. An authentication bypass vulnerability in its API allows attackers to bypass login controls and gain unauthorized access to privilege management functions, potentially enabling them to modify backup policies, steal backed-up data, or disrupt recovery operations without providing valid credentials.
Technical details
The vulnerability is an authentication bypass in the Command Center API that affects privilege management. The flaw allows unauthenticated or improperly authenticated requests to access protected API endpoints, bypassing the normal authentication checks. This is a network-reachable vulnerability with no authentication required to exploit. Attackers can leverage this to escalate privileges and access sensitive administrative functions. Patches have been released for affected versions (11.36.123+, 11.40.72+, 11.44.20+, 11.46.20+), and users should upgrade to the resolved maintenance releases immediately.
Affected products
- Commvault Command Center 11.36.0 - 11.36.122, 11.40.0 - 11.40.71, 11.44.0 - 11.44.19, 11.46.0 - 11.46.19
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Resolved versions available: 11.36.123+, 11.40.72+, 11.44.20+, 11.46.20+