logo

CVE-2026-29200: A 9.9 CVSS Comet Backup Flaw Granting Total Cross-Tenant Takeover

ID: a1565d82-a380-524b-8adb-40964dc15063

STIX ID: report--a1565d82-a380-524b-8adb-40964dc15063

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Ddos

...
...

Comet Backup disclosed CVE-2026-29200, a critical IDOR in its server API (CVSS 9.9) that can let a tenant administrator impersonate and take over end-user accounts across tenants; the flaw affects roughly six years of releases (notably versions 20.11.0–26.1.1 and 26.2.1), Comet has patched hosted servers and urges self-hosted administrators to update immediately to 26.1.2, 26.2.2 or later, and the issue was responsibly reported by the A Security team.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.