CVE-2026-29200Disclosure

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows a tenant administrator to impersonate any end-user account of other tenants on the same server via a vulnerable API call.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-04); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-04: 2Mentions · 2026-05-15: 1Technical Details · 2026-05-04: 2Technical Details · 2026-05-15: 105-0405-15
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-042
Disclosure2
2026-05-151
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-29200 A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows a tenant administ… https://www.cve.org/CVERecord?id=CVE-2026-29200

    Post summary

    The text announces a critical IDOR vulnerability in Comet Backup across multiple versions, but lacks PoC, exploit, or mitigation details.

    00010181
    57.4K followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    A critical IDOR vulnerability (CVE-2026-29200) affects Comet Backup versions 20.11.0 to 26.1.1 and 26.2.1, risking tenant impersonation via API. Review and update your backup software promptly to protect sensitive data. #cybersecurity

    Post summary

    A new IDOR vulnerability (CVE-2026-29200) in Comet Backup is announced with affected versions and implications, advising users to update but providing no PoC, exploit, or active exploitation evidence.

    0000047
    80 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-29200 Critical IDOR Vulnerability in Comet Backup Allows Cross-Tenant Account Impersonation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29200

    Post summary

    The text announces CVE‑2026‑29200, a critical IDOR flaw in Comet Backup that can enable cross‑tenant account impersonation, but it provides no proof‑of‑concept, exploit code, or mitigation details.

    0000056
    4.0K followersView on X

Explore more