
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-77103 is an authentication bypass vulnerability in Commvault's CommServe component, classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel). It allows unauthenticated remote attackers to circumvent access authorization controls and disclose sensitive information. The vulnerability affects Commvault/Commvault Cloud versions 11.36.0–11.36.122, 11.40.0–11.40.71, 11.44.0–11.44.19, and 11.46.0–11.46.19. It was published on September 8, 2026, with a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Commvault Advisory).
The root cause is an alternate path or channel within CommServe that bypasses the product's authentication requirements (CWE-288). An unauthenticated attacker can reach this alternate path over the network without any privileges or user interaction, allowing them to access protected resources or functionality that should require valid credentials. No public technical write-ups or proof-of-concept code detailing the specific endpoint or bypass mechanism have been published as of the time of this report (GitHub Advisory, Commvault Advisory).
Successful exploitation allows an unauthenticated remote attacker to bypass CommServe's access authorization controls and disclose sensitive information managed by the system. The impact is limited to confidentiality — integrity and availability of the vulnerable system are not directly affected. Given that CommServe is the central management server for Commvault backup and data protection environments, exposed data may include backup configurations, credentials, or other sensitive operational data that could facilitate further attacks (GitHub Advisory, Commvault Advisory).
As of the time of this report, there is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation (GitHub Advisory). No threat actor attribution has been identified. The EPSS score is approximately 0.33% (22nd percentile), indicating a currently low probability of exploitation within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. NVD's SSVC assessment also classifies exploitation as "none" at this time (Commvault Advisory).
Commvault has released patched maintenance releases addressing this vulnerability. Affected customers should upgrade CommServe to the following fixed versions or later: 11.36.123 (for the 11.36.x branch), 11.40.72 (for the 11.40.x branch), 11.44.20 (for the 11.44.x branch), and 11.46.20 (for the 11.46.x branch). No specific configuration-based workaround has been published; upgrading to the resolved maintenance release is the recommended remediation (Commvault Advisory, GitHub Advisory).
Coverage of CVE-2026-77103 has been limited to automated vulnerability tracking platforms and aggregators such as VulDB, CVEFeed, and Tenable's plugin pipeline. A brief mention was noted on Bluesky via the CyberHub blog. No significant researcher commentary, vendor blog posts, or major media coverage has been identified beyond the official Commvault security advisory (Commvault Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."