CVE-2026-77091
—Path Traversal in DataCube Bypasses Security Feature Enforcement
CVE-2026-77091 is a path traversal flaw (CWE-22) in DataCube that affects the enforcement of the product's security features, allowing traversal outside intended directories in a way that bypasses access controls. Per the CVSS 4.0 vector (AV:L/PR:L/UI:N), exploitation requires local access with low privileges and no user interaction, and it yields high confidentiality, integrity, and availability impact on the affected system with no impact spreading to other systems. Customers running DataCube are affected, and the vendor's advisory directs them to a resolved maintenance release and specifically to update the Content Extractor and Index Store components. The source data does not state which versions are vulnerable or the exact fixed version, only that a maintenance release resolving the issue is available. Exploitation is not currently known: there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.1% probability of exploitation in the next 30 days (3rd percentile).
What to do: Upgrade DataCube to the resolved maintenance release identified by the vendor, ensuring that both the Content Extractor and Index Store components are updated as the advisory requires, and consult the vendor advisory for the exact fixed version, which is not stated here. Because exploitation requires local low-privileged access, restrict local accounts on affected hosts and verify that directory-restriction controls remain enforced until the patch is applied. No public proof-of-concept exists, so defender attention can focus on patching rather than active compromise detection, though monitoring for unusual file access outside DataCube's working directories is prudent.
| DataCube (including Content Extractor and Index Store components) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and Index Store.
- Vendors
- commvault
- Products
- commvault
- Weakness
- CWE-22
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.