CVE-2026-77101
largeStack-based buffer overflow in Commvault CommServe causes service disruption
Commvault CommServe contains a stack-based buffer overflow (CWE-121) that is reachable over the network without authentication or user interaction, according to the CVSS 4.0 vector. Successful triggering of the flaw crashes or disrupts the CommServe service, producing a high impact on availability; confidentiality and integrity are not affected, so the primary gain for an attacker is denial of service against the customer's backup and data-management control plane. CommServe is the central management server in Commvault deployments, so any organization running an affected build is exposed, and an outage could stall backup, restore, and scheduling operations across the estate. As of now there is no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS places 30-day exploitation probability at roughly 0.3% (17th percentile). The vendor states the issue is resolved in a maintenance release and directs customers to update CommServe.
What to do: Upgrade CommServe to the maintenance release identified by Commvault as containing the fix, since the advisory does not name a specific version. Until patched, restrict network access to the CommServe service to trusted management networks and monitor for service crashes or restarts. Because there are no public PoCs or known exploitation, prioritize this update within normal patching cycles rather than as an emergency.
| Commvault CommServe | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
- Vendors
- commvault
- Products
- commvault
- Weakness
- CWE-121
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.