CVE-2026-77105
largeCryptographic signature verification flaw in Commvault CommServe privilege management
CVE-2026-77105 is an improper cryptographic signature verification issue (CWE-347) in Commvault's CommServe that affects privilege management. The CVSS 4.0 vector indicates it is exploitable over the network with low privileges (an existing low-privileged account), without user interaction or special complexity, and can result in high impact to the confidentiality, integrity, and availability of the CommServe. An attacker with such an account could abuse the flawed signature checks that underpin privilege decisions, potentially gaining unauthorized elevated access to the backup management infrastructure. Affected are organizations running Commvault CommServe with its Web Server, and the vendor directs customers to a resolved maintenance release. No exploitation is known: there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts the 30-day exploitation probability at about 0.2%.
What to do: Upgrade CommServe and the Web Server to the resolved maintenance release identified in Commvault's advisory, since specific affected and fixed version numbers are not provided in the available data. Until patched, restrict access to CommServe and Web Server interfaces from untrusted networks and audit low-privileged accounts, because exploitation requires an existing account. Confirm your current CommServe build against Commvault's security advisory for the exact affected and fixed versions.
| commvault CommServe (including Web Server) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.
- Vendors
- commvault
- Products
- commvault
- Weakness
- CWE-347
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.