ZeroHour

CVE-2026-77103

large

Authentication bypass in Commvault CommServe enables information disclosure

CVSS 4.0
8.7 high
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-77103 is an authentication bypass (CWE-288) in Commvault's CommServe, the central management component of Commvault's data-protection software, affecting access authorization checks. Per the CVSS 4.0 vector, it is exploitable over the network by an unauthenticated attacker with no user interaction or special conditions, meaning anyone who can reach the CommServe service can bypass authentication directly. The impact is confidentiality-only: an attacker gains unauthorized access to information held by or served through CommServe (high confidentiality impact), with no integrity or availability impact. Affected are customers running CommServe; the available data does not specify affected version ranges, and Commvault states the issue is resolved in a maintenance release. There are no reports of in-the-wild exploitation, no known public proof-of-concept, and EPSS estimates the 30-day exploitation probability at about 0.3%, so current risk is driven by exposure rather than observed attacks.

What to do: Upgrade CommServe to the maintenance release that resolves this issue as directed by Commvault's security advisory (exact fixed versions are not listed in the available data). Until patched, restrict network access to the CommServe service to trusted management networks, avoid direct internet exposure, and review access logs for unauthenticated connections. Because the impact is information disclosure, verify whether any sensitive configuration, inventory, or environment data was exposed.

Affected
Commvault CommServe
Estimated exposure
large≈ tens of thousands of CommServe deployments (order of 10k–100k installations), of which only a smaller subset is internet-exposed — CommServe is the required central component in every Commvault on-prem data-protection deployment and Commvault's enterprise installed base is on the order of tens of thousands of organizations, but this is a deployment-pattern estimate,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.

Vendors
commvault
Products
commvault
Weakness
CWE-288
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.