Report: CVE-2026-29200 - Comet Backup Tenant Impersonation IDOR

Report: CVE-2026-29200 - Comet Backup Tenant Impersonation IDOR

CVE ID :CVE-2026-29200 Published : May 4, 2026, 7:16 a.m. | 51 minutes ago Description :A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows a tenant administrator to impersonate any end-user account of other tenants on the same server via a vulnerable API call. Severity: 9.9 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
CRITICAL
Published
May 4, 2026