CVE-2026-77104
largePath Traversal Information Disclosure in Commvault CommServe
Commvault's CommServe (the central management server of the Commvault data-protection platform) contains a path traversal flaw (CWE-22) that allows an attacker to access files or data outside the intended directory, resulting in information disclosure. Per the CVSS 4.0 vector, the issue is exploitable over the network with no privileges or user interaction required, but with high attack complexity and additional attack requirements, making successful exploitation comparatively difficult; the primary impact is high in confidentiality with a low integrity component. An attacker who successfully exploits it could read sensitive data (potentially including configuration or backup-related files) from the CommServe host. Customers running CommServe are affected and are advised to move to the resolved maintenance release. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts the 30-day exploitation probability at about 0.3%, so no active exploitation is currently known.
What to do: Upgrade CommServe to the maintenance release identified in Commvault's advisory (the source data does not include specific version numbers, so confirm the fixed version with the vendor bulletin before patching). In the meantime, limit network access to the CommServe server and its web console to trusted management networks and avoid exposing it directly to the internet. Monitor the vendor's channel for an updated advisory, PoC, or evidence of exploitation given the current low EPSS score.
| Commvault CommServe (Commvault data-protection platform) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
- Vendors
- commvault
- Products
- commvault
- Weakness
- CWE-22
- Vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.