ZeroHour

CVE-2026-77105

large

Cryptographic signature verification flaw in Commvault CommServe privilege management

CVSS 4.0
8.7 high
EPSS
<1%p7
Published
()
Modified
AI analysis

CVE-2026-77105 is an improper cryptographic signature verification issue (CWE-347) in Commvault's CommServe that affects privilege management. The CVSS 4.0 vector indicates it is exploitable over the network with low privileges (an existing low-privileged account), without user interaction or special complexity, and can result in high impact to the confidentiality, integrity, and availability of the CommServe. An attacker with such an account could abuse the flawed signature checks that underpin privilege decisions, potentially gaining unauthorized elevated access to the backup management infrastructure. Affected are organizations running Commvault CommServe with its Web Server, and the vendor directs customers to a resolved maintenance release. No exploitation is known: there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts the 30-day exploitation probability at about 0.2%.

What to do: Upgrade CommServe and the Web Server to the resolved maintenance release identified in Commvault's advisory, since specific affected and fixed version numbers are not provided in the available data. Until patched, restrict access to CommServe and Web Server interfaces from untrusted networks and audit low-privileged accounts, because exploitation requires an existing account. Confirm your current CommServe build against Commvault's security advisory for the exact affected and fixed versions.

Affected
commvault CommServe (including Web Server)
Estimated exposure
largeon the order of tens of thousands of CommServe deployments worldwide, with actual exposure limited to installations on affected versions — Commvault's enterprise customer base is on the order of tens of thousands of organizations and a CommServe is typically deployed once per customer environment as a central management server, though internet-exposed instances are likely a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.

Vendors
commvault
Products
commvault
Weakness
CWE-347
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.