
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-77104 is a path traversal vulnerability in Commvault's CommServe component that allows unauthenticated remote attackers to read sensitive files outside the intended directory structure, resulting in information disclosure. It affects Commvault Cloud versions 11.36.0–11.36.122, 11.40.0–11.40.71, 11.44.0–11.44.19, and 11.46.0–11.46.19. The vulnerability was published on September 8, 2026, with a patch available in the corresponding maintenance releases. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.3 (High) (GitHub Advisory, Commvault Advisory).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal), meaning CommServe fails to properly neutralize special path elements (e.g., ../) in user-supplied input used to construct file system paths. An unauthenticated attacker can send a crafted network request to the CommServe service, supplying a malicious path that resolves outside the intended restricted directory, thereby reading arbitrary files. Exploitation requires no privileges or user interaction, though attack complexity is rated High (CVSS v4.0) due to the presence of attack requirements (specific deployment conditions must be met). No public proof-of-concept code has been identified (GitHub Advisory, Commvault Advisory).
Successful exploitation allows an unauthenticated attacker to read sensitive files and configuration data from the CommServe system that should not be externally accessible, resulting in high confidentiality impact. Because CommServe is the central management server for Commvault backup environments, exposed configuration files could contain credentials, encryption keys, or backup job metadata, potentially enabling further lateral movement or privilege escalation within the environment. Integrity and availability of the CommServe system are not directly impacted by this vulnerability (GitHub Advisory, Commvault Advisory).
As of the time of publication, there is no evidence of active in-the-wild exploitation and no public proof-of-concept exploit has been identified (Feedly). The EPSS score is approximately 0.34–0.37%, placing it in roughly the 31st percentile for exploitation likelihood within 30 days. The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable. CVE-2026-77104 does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (GitHub Advisory).
../../, URL-encoded variants such as %2e%2e%2f, or alternate encodings) in the relevant parameter to escape the intended directory.../, %2e%2e%2f, %2e%2e/, or ..%2f in URL parameters or request bodies; unexpected inbound connections to CommServe from external or untrusted IP addresses.Commvault has released patched maintenance releases addressing this vulnerability. Customers should upgrade CommServe to version 11.36.123 or later (for the 11.36 branch), 11.40.72 or later (11.40 branch), 11.44.20 or later (11.44 branch), or 11.46.20 or later (11.46 branch). As a compensating control, organizations should implement network access controls to restrict access to CommServe systems to trusted hosts only, and monitor file access logs for path traversal patterns. Applying the principle of least privilege to service accounts and user permissions is also recommended (Commvault Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."