Commvault Cloud
Command Center API authentication bypass, fixed builds available (Commvault Cloud)
The Cyber Centre published AV26-895 on 2026-09-08 pointing at Commvault bulletin CV_2026_07_1, a Command Center API authentication bypass with fixed builds already available; backup platforms are a prime ransomware precursor target, so an unauthenticated bypass on the management API warrants same-day patching.
Commvault's bulletin CV_2026_07_1, relayed by the Canadian Centre for Cyber Security as AV26-895, describes an authentication bypass in the Command Center API of Commvault Cloud 11.36, 11.40, 11.44 and 11.46 feature releases prior to the listed maintenance builds. An attacker who can reach the Command Center API could act without valid credentials on the backup control plane. No CVE, CVSS score or statement exploitation appears in the advisory text, and the bulletin's technical details were not retrieved in this pass.
Affected: Commvault Cloud 11.36.0 prior to 11.36.123, 11.40.0 prior to 11.40.72, 11.44.0 prior to 11.44.20, 11.46.0 prior to 11.46.20
In Command Center, check the installed version ( / CommServe version). Any 11.36.x below 11.36.123, 11.40.x below 11.40.72, 11.44.x below 11.44.20 or 11.46.x below 11.46.20 is affected. Confirm from the network whether the Command Center web/API ports are reachable from untrusted segments or the internet.
Apply the maintenance release for your feature release: 11.36.123, 11.40.72, 11.44.20 or 11.46.20 or later, as listed in Commvault's CV_2026_07_1. If you cannot update today, place the Command Center API behind a VPN or allowlist and audit recent API activity for sessions from unexpected sources.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
