ZeroHour

CVE-2026-77104

large

Path Traversal Information Disclosure in Commvault CommServe

CVSS 4.0
8.3 high
EPSS
<1%p31
Published
()
Modified
AI analysis

Commvault's CommServe (the central management server of the Commvault data-protection platform) contains a path traversal flaw (CWE-22) that allows an attacker to access files or data outside the intended directory, resulting in information disclosure. Per the CVSS 4.0 vector, the issue is exploitable over the network with no privileges or user interaction required, but with high attack complexity and additional attack requirements, making successful exploitation comparatively difficult; the primary impact is high in confidentiality with a low integrity component. An attacker who successfully exploits it could read sensitive data (potentially including configuration or backup-related files) from the CommServe host. Customers running CommServe are affected and are advised to move to the resolved maintenance release. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts the 30-day exploitation probability at about 0.3%, so no active exploitation is currently known.

What to do: Upgrade CommServe to the maintenance release identified in Commvault's advisory (the source data does not include specific version numbers, so confirm the fixed version with the vendor bulletin before patching). In the meantime, limit network access to the CommServe server and its web console to trusted management networks and avoid exposing it directly to the internet. Monitor the vendor's channel for an updated advisory, PoC, or evidence of exploitation given the current low EPSS score.

Affected
Commvault CommServe (Commvault data-protection platform)
Estimated exposure
largelikely on the order of tens of thousands of CommServe deployments worldwide (roughly one per customer environment), with likely only a subset internet-exposed — Commvault is a widely deployed enterprise backup and recovery platform and every customer environment runs at least one CommServe server, though these are typically deployed inside corporate networks rather than exposed to the internet, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.

Vendors
commvault
Products
commvault
Weakness
CWE-22
Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.