CVE-2026-77103
largeAuthentication bypass in Commvault CommServe enables information disclosure
CVE-2026-77103 is an authentication bypass (CWE-288) in Commvault's CommServe, the central management component of Commvault's data-protection software, affecting access authorization checks. Per the CVSS 4.0 vector, it is exploitable over the network by an unauthenticated attacker with no user interaction or special conditions, meaning anyone who can reach the CommServe service can bypass authentication directly. The impact is confidentiality-only: an attacker gains unauthorized access to information held by or served through CommServe (high confidentiality impact), with no integrity or availability impact. Affected are customers running CommServe; the available data does not specify affected version ranges, and Commvault states the issue is resolved in a maintenance release. There are no reports of in-the-wild exploitation, no known public proof-of-concept, and EPSS estimates the 30-day exploitation probability at about 0.3%, so current risk is driven by exposure rather than observed attacks.
What to do: Upgrade CommServe to the maintenance release that resolves this issue as directed by Commvault's security advisory (exact fixed versions are not listed in the available data). Until patched, restrict network access to the CommServe service to trusted management networks, avoid direct internet exposure, and review access logs for unauthenticated connections. Because the impact is information disclosure, verify whether any sensitive configuration, inventory, or environment data was exposed.
| Commvault CommServe | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
- Vendors
- commvault
- Products
- commvault
- Weakness
- CWE-288
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.