CVE-2026-77102: 
Commvault vulnerability analysis and mitigation

Overview

CVE-2026-77102 is a heap-based buffer overflow vulnerability in Commvault's CommServe component that allows unauthenticated remote attackers to crash the CommServe service, resulting in a denial of service. It was published on September 8, 2026, and affects Commvault Cloud versions 11.36.0–11.36.122, 11.40.0–11.40.71, 11.44.0–11.44.19, and 11.46.0–11.46.19. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Commvault Advisory).

Technical details

The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow), where the CommServe service fails to properly validate or bound-check input, allowing malformed network data to overflow a heap-allocated buffer. Because the attack vector is network-accessible with no authentication, no privileges, and no user interaction required, it is highly automatable. Exploitation causes the CommServe service process to crash due to memory corruption in the heap region. No public proof-of-concept or detailed technical write-up has been identified at this time (GitHub Advisory, Commvault Advisory).

Impact

Successful exploitation results in a denial of service by crashing the CommServe service, disrupting backup and data management operations managed by Commvault. There is no evidence of confidentiality or integrity impact — the vulnerability is limited to availability. Because CommServe acts as the central management server for Commvault environments, its unavailability can halt all backup, restore, and data protection workflows across the enterprise (GitHub Advisory, Commvault Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.257%, placing it in the 19th percentile for exploitation likelihood within 30 days. The vulnerability is rated as automatable by NVD SSVC analysis, meaning it could be scripted for mass exploitation if a PoC were to emerge. No threat actor attribution has been reported, and the CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Mitigation and workarounds

Commvault has released patched maintenance releases addressing this vulnerability. Customers should upgrade CommServe to version 11.36.123 or later (for the 11.36 branch), 11.40.72 or later (for the 11.40 branch), 11.44.20 or later (for the 11.44 branch), or 11.46.20 or later (for the 11.46 branch). Patches are available through official Commvault channels. As a network-level workaround, organizations should restrict access to CommServe network ports to trusted hosts and management networks only until patching is complete (Commvault Advisory, GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Commvault vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77105HIGH8.7
  • Commvault logoCommvault
  • cpe:2.3:a:commvault:commvault
NoYesSep 08, 2026
CVE-2026-77103HIGH8.7
  • Commvault logoCommvault
  • cpe:2.3:a:commvault:commvault
NoYesSep 08, 2026
CVE-2026-77102HIGH8.7
  • Commvault logoCommvault
  • cpe:2.3:a:commvault:commvault
NoYesSep 08, 2026
CVE-2026-77104HIGH8.3
  • Commvault logoCommvault
  • cpe:2.3:a:commvault:commvault
NoYesSep 08, 2026
CVE-2026-77106HIGH7.7
  • Commvault logoCommvault
  • cpe:2.3:a:commvault:commvault
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management