PatchSiren cyber security CVE debrief
CVE-2026-44926 Veritas CVE debrief
CVE-2026-44926 is a high-severity access-control weakness in InfoScale CmdServer before 7.4.2. The NVD entry assigns a CVSS 8.8 score and describes a network-reachable issue that can be triggered with low privileges and no user interaction, with potential high impact to confidentiality, integrity, and availability.
- Vendor
- Veritas
- Product
- InfoScale Command Server
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-20
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-20
- Advisory updated
- 2026-07-23
Who should care
Administrators and security teams responsible for InfoScale CmdServer deployments should review this issue first, especially where the service is reachable from broader internal networks or exposed administrative segments.
Technical summary
NVD currently lists the vulnerability status as "Awaiting Analysis" and maps the issue to CWE-284 (Improper Access Control). The supplied CVSS vector, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicates a remotely reachable issue requiring low privileges and no user interaction, with high impact across confidentiality, integrity, and availability. The NVD record also references vendor-facing security bulletin material and a Veritas support document for remediation context.
Defensive priority
High
Recommended defensive actions
- Confirm whether any InfoScale CmdServer instance is running a version earlier than 7.4.2.
- Review the vendor security bulletin and the referenced Veritas support document for the recommended remediation path.
- Upgrade affected systems to the fixed release identified by the vendor and verify the change across all affected nodes.
- Until remediation is complete, limit network exposure and restrict access to trusted administrative users and management networks.
- Audit CmdServer access-control configuration and review authentication and authorization logs for unexpected activity.
- Monitor the CVE record and NVD entry for status updates or additional vendor guidance.
Evidence notes
The supplied source corpus shows CVE publication and modification on 2026-05-20. NVD metadata lists vulnStatus "Awaiting Analysis," CVSS vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, and weakness CWE-284. The CVE references include an InfoScale security bulletin URL and a Veritas support URL, which are the only official references supplied here. No KEV entry or ransomware-campaign use is provided in the corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-44926 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-44926
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-44926 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44926
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.veritas.com/support/en_US/doc/109864724-141543588-0/v141217547-141543588
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.