CVE-2026-29200: WebPros Comet Backup

Critical severity, CVSS 9.9. EPSS: 0.5% chance of exploitation in the next 30 days.

A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows a tenant administrator to impersonate any end-user account of other tenants on the same server via a vulnerable API call.

Affected products

  • WebPros Comet Backup: from 20.11.0, before 26.1.2 (fixed in 26.1.2); from 26.2.0, before 26.2.2 (fixed in 26.2.2)

Published 2026-05-04. Last modified 2026-06-17.