ZeroHour
Story · 1 source · 1 articlefirst updated ()

Canadian Centre for Cyber Security warns Commvault Cloud Command Center API authentication bypass affects builds before 11.36.123, 11.40.72, 11.44.20, 11.46.20

mediumAdvisoryimportance 32
What's new: Second advisory (AV26-899, 2026-09-09) reiterated the same affected branches (36.0/40.0/44.0/46.0) and fixed builds (11.36.123/11.40.72/11.44.20/11.46.20) but described the issues only as 'vulnerabilities' without naming CV_2026_07_1 or providing CVE IDs, severity scores, or exploitation details; no new technical details or indicators were added.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Canada's Cyber Centre issued advisories AV26-895 (Sept 8, 2026) and AV26-899 (Sept 9, 2026) stating Commvault Cloud releases 11.36, 11.40, 11.44 and 11.46 are affected before fixed builds 11.36.123, 11.40.72, 11.44.20 and 11.46.20; the more specific advisory…

The Canadian Centre for Cyber Security published two advisories about Commvault Cloud. Advisory AV26-895 (2026-09-08T18:11:59Z) states that Commvault Cloud versions 11.36, 11.40, 11.44 and 11.46 prior to fixed builds 11.36.123, 11.40.72, 11.44.20 and 11.46.20 are affected by issue CV_2026_07_1, described as a Command Center API authentication bypass. Advisory AV26-899 (2026-09-09T13:59:24Z) states Commvault Cloud is affected by vulnerabilities as of September 8, 2026, listing the same affected branches (36.0, 40.0, 44.0, 46.0) and the same fixed builds (11.36.123, 11.40.72, 11.44.20, 11.46.20), but it does not name CVE identifiers, severity ratings, or exploitation details and does not repeat the CV_2026_07_1 issue designation. The two advisories agree on affected versions and fixed builds; the first is more specific about the nature of the issue, while the second describes the problems only generically as 'vulnerabilities.' Both advisories link to Commvault's own security advisories and urge administrators to review the vendor advisories and apply the available updates.

  • Source: Canadian Centre for Cyber Security, advisories AV26-895 (2026-09-08T18:11:59Z) and AV26-899 (2026-09-09T13:59:24Z).
  • Affected product: Commvault Cloud (Command Center), as of September 8, 2026.
  • Affected branches/versions: 11.36 (36.0), 11.40 (40.0), 11.44 (44.0) and 11.46 (46.0).
  • Fixed builds: 11.36.123, 11.40.72, 11.44.20 and 11.46.20.
  • Issue identified in AV26-895: CV_2026_07_1, a Command Center API authentication bypass.
  • AV26-899 provides no CVE identifiers, severity ratings, or exploitation details and does not name the specific issue; it links to Commvault's own advisories.
  • Recommended action: review Commvault's security advisories and apply the available updates to the fixed builds.

Coverage timeline

  1. · 8d ago
    Canadian Centre for Cyber Security· 32
    Commvault security advisory (AV26-895)

    Canada's Cyber Centre advisory AV26-895 warns Commvault Cloud builds before 11.36.123/11.40.72/11.44.20/11.46.20 are affected by a Command Center API authentication bypass.