ZeroHour

CVE-2026-77089

Authentication bypass in Command Center API grants unauthorized privileged access

CVSS 4.0
9.3 critical
EPSS
<1%p26
Published
()
Modified
AI analysis

CVE-2026-77089 is an authentication bypass flaw (CWE-290, authentication bypass by alternate path or channel) in the Command Center API, affecting how privileges are managed. Per the CVSS 4.0 vector, it is remotely exploitable over the network (AV:N) with low attack complexity and no prior privileges or user interaction required (PR:N/UI:N), so a single unauthenticated request to the API can trigger it. A successful attacker gains unauthorized access to privileged functionality, and the critical 9.3 rating with high confidentiality, integrity, and availability impacts indicates this could escalate to broad unauthorized control of the affected system. Affected users are customers running the affected Command Center software; the advisory directs all customers to upgrade to the resolved maintenance release but does not name the vendor or publish specific version ranges. Exploitation status: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS assigns a 0.3% probability of exploitation within 30 days (percentile 26), indicating no known exploitation so far.

What to do: Upgrade Command Center to the maintenance release issued by the vendor; consult the vendor's advisory for the exact fixed version, since no version numbers were specified in this data. Until patched, restrict network exposure of the Command Center API (firewall/ACL rules or segmentation) because the flaw is exploitable remotely without credentials or user interaction. Review API and audit logs for unauthenticated requests performing privileged operations, which would indicate possible prior exploitation.

Affected
Command Center API
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.

Vendors
commvault
Products
commvault
Weakness
CWE-290
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.