CVE-2026-29200: WebPros Comet Backup
Critical severity, CVSS 9.9. EPSS: 0.5% chance of exploitation in the next 30 days.
A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows a tenant administrator to impersonate any end-user account of other tenants on the same server via a vulnerable API call.
Affected products
- WebPros Comet Backup: from 20.11.0, before 26.1.2 (fixed in 26.1.2); from 26.2.0, before 26.2.2 (fixed in 26.2.2)
Published 2026-05-04. Last modified 2026-06-17.