ZeroHour

CVE-2026-77106

large

Missing Authorization in Commvault cvlaunchd Allows Unauthorized Command Execution

CVSS 4.0
7.7 high
EPSS
<1%p18
Published
()
Modified
AI analysis

Commvault's cvlaunchd component contains a missing authorization flaw (CWE-862) in its command execution authorization logic, meaning an actor with network access and low privileges can trigger command execution without the required authorization check. The CVSS 4.0 vector (network vector, high attack complexity, low privileges required) indicates exploitation requires some level of access to the Commvault environment but no user interaction. A successful attacker gains command execution with high impact on the confidentiality, integrity, and availability of the affected system. All Commvault installations are affected, including CommServe, Web Server, Command Center, Media Agents, Clients, and HyperScale X, and customers must upgrade to the resolved maintenance release. There is currently no known exploitation: no public proof-of-concept, not listed in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Update all Commvault installations — CommServe, Web Server, Command Center, Media Agents, Clients, and HyperScale X — to the resolved maintenance release; consult the Commvault security advisory for the exact fixed build, which is not specified here. Until patched, restrict network access to Commvault services (especially internet-facing CommServe and Command Center instances) to trusted management networks, and verify whether low-privilege accounts can reach cvlaunchd. No public exploit is known, but the multi-component footprint means patching should be treated as fleet-wide rather than limited to the primary server.

Affected
Commvault CommServe
Commvault Web Server
Commvault Command Center
Commvault Media Agents
Commvault Clients
Commvault HyperScale X
Estimated exposure
largeTens of thousands of enterprise installations (Commvault serves a customer base on the order of tens of thousands, with each deployment running multiple… — Commvault is widely deployed enterprise backup software with a customer base in the tens of thousands, and the advisory directs every installation type (CommServe, Media Agents, Clients, HyperScale X) to update, so affected systems likely…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.

Vendors
commvault
Products
commvault
Weakness
CWE-862
Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.