Commvault security advisory (AV26-895)
Canada's Cyber Centre advisory AV26-895 warns Commvault Cloud builds before 11.36.123/11.40.72/11.44.20/11.46.20 are affected by a Command Center API authentication bypass.
The Canadian Centre for Cyber Security alerted users that Commvault Cloud versions 11.36, 11.40, 11.44 and 11.46, prior to fixed builds 11.36.123, 11.40.72, 11.44.20 and 11.46.20, are affected by issue CV_2026_07_1, a Command Center API authentication bypass. Administrators are encouraged to review the linked vendor advisories and apply the available updates.
- Affects Commvault Cloud 11.36-11.46; issue CV_2026_07_1 is a Command Center API authentication bypass.
- Fixed builds: 11.36.123, 11.40.72, 11.44.20, 11.46.20; admins urged to update.
Full article71 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-895
Date: September 8, 2026
As of September 8, 2026, Commvault is affected by vulnerabilities in the following product:
- Commvault Cloud
- 11.36.0 Prior to 11.36.123
- 11.40.0 Prior to 11.40.72
- 11.44.0 Prior to 11.44.20
- 11.46.0 Prior to 11.46.20
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/commvault-security-advisory-av26-895