← Back to CVE List
CVE-2026-29200NVD
Vulnerability Summary
A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows a tenant administrator to impersonate any end-user account of other tenants on the same server via a vulnerable API call.
CVSS v4.0 Base Metrics — Score 9.9 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)None
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)High
Affected & Patched Versions
- WebPros Comet Backup >= 20.11.0 and < 26.1.2
- WebPros Comet Backup >= 26.2.0 and < 26.2.2
- WebPros Comet Backup 26.1.2
- WebPros Comet Backup 26.2.2