CVE-2026-77106
largeMissing Authorization in Commvault cvlaunchd Allows Unauthorized Command Execution
Commvault's cvlaunchd component contains a missing authorization flaw (CWE-862) in its command execution authorization logic, meaning an actor with network access and low privileges can trigger command execution without the required authorization check. The CVSS 4.0 vector (network vector, high attack complexity, low privileges required) indicates exploitation requires some level of access to the Commvault environment but no user interaction. A successful attacker gains command execution with high impact on the confidentiality, integrity, and availability of the affected system. All Commvault installations are affected, including CommServe, Web Server, Command Center, Media Agents, Clients, and HyperScale X, and customers must upgrade to the resolved maintenance release. There is currently no known exploitation: no public proof-of-concept, not listed in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Update all Commvault installations — CommServe, Web Server, Command Center, Media Agents, Clients, and HyperScale X — to the resolved maintenance release; consult the Commvault security advisory for the exact fixed build, which is not specified here. Until patched, restrict network access to Commvault services (especially internet-facing CommServe and Command Center instances) to trusted management networks, and verify whether low-privilege accounts can reach cvlaunchd. No public exploit is known, but the multi-component footprint means patching should be treated as fleet-wide rather than limited to the primary server.
| Commvault CommServe | — |
| Commvault Web Server | — |
| Commvault Command Center | — |
| Commvault Media Agents | — |
| Commvault Clients | — |
| Commvault HyperScale X | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
- Vendors
- commvault
- Products
- commvault
- Weakness
- CWE-862
- Vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.