A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows a tenant administrator to impersonate any end-user account of other tenants on the same server via a vulnerable API call.
CVSS
No CVSS.
References
Configurations
No configuration.
History
04 May 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-04 07:16
Updated : 2026-05-06 19:05
NVD link : CVE-2026-29200
Mitre link : CVE-2026-29200
CVE.ORG link : CVE-2026-29200
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
