CVE-2026-77104: 
Commvault vulnerability analysis and mitigation

Overview

CVE-2026-77104 is a path traversal vulnerability in Commvault's CommServe component that allows unauthenticated remote attackers to read sensitive files outside the intended directory structure, resulting in information disclosure. It affects Commvault Cloud versions 11.36.0–11.36.122, 11.40.0–11.40.71, 11.44.0–11.44.19, and 11.46.0–11.46.19. The vulnerability was published on September 8, 2026, with a patch available in the corresponding maintenance releases. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.3 (High) (GitHub Advisory, Commvault Advisory).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal), meaning CommServe fails to properly neutralize special path elements (e.g., ../) in user-supplied input used to construct file system paths. An unauthenticated attacker can send a crafted network request to the CommServe service, supplying a malicious path that resolves outside the intended restricted directory, thereby reading arbitrary files. Exploitation requires no privileges or user interaction, though attack complexity is rated High (CVSS v4.0) due to the presence of attack requirements (specific deployment conditions must be met). No public proof-of-concept code has been identified (GitHub Advisory, Commvault Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to read sensitive files and configuration data from the CommServe system that should not be externally accessible, resulting in high confidentiality impact. Because CommServe is the central management server for Commvault backup environments, exposed configuration files could contain credentials, encryption keys, or backup job metadata, potentially enabling further lateral movement or privilege escalation within the environment. Integrity and availability of the CommServe system are not directly impacted by this vulnerability (GitHub Advisory, Commvault Advisory).

Exploitability

As of the time of publication, there is no evidence of active in-the-wild exploitation and no public proof-of-concept exploit has been identified (Feedly). The EPSS score is approximately 0.34–0.37%, placing it in roughly the 31st percentile for exploitation likelihood within 30 days. The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable. CVE-2026-77104 does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible CommServe instances running Commvault Cloud versions 11.36.0–11.36.122, 11.40.0–11.40.71, 11.44.0–11.44.19, or 11.46.0–11.46.19 using network scanning tools or Shodan.
  2. Identify vulnerable endpoint: Locate the CommServe web service or API endpoint that accepts file path parameters without requiring authentication.
  3. Craft path traversal payload: Construct a request containing path traversal sequences (e.g., ../../, URL-encoded variants such as %2e%2e%2f, or alternate encodings) in the relevant parameter to escape the intended directory.
  4. Send malicious request: Submit the crafted HTTP request to the CommServe service. If the server fails to sanitize the path, it will resolve the traversal sequence and return the contents of the targeted file.
  5. Exfiltrate sensitive data: Read returned file contents, which may include configuration files, credentials, encryption keys, or other sensitive CommServe data that can be leveraged for further attacks (GitHub Advisory, Commvault Advisory).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to CommServe endpoints containing path traversal sequences such as ../, %2e%2e%2f, %2e%2e/, or ..%2f in URL parameters or request bodies; unexpected inbound connections to CommServe from external or untrusted IP addresses.
  • Logs: CommServe access logs showing requests with encoded or literal directory traversal patterns; HTTP responses returning file contents from outside expected application directories; repeated 200 OK responses to requests targeting sensitive system paths.
  • File System: Evidence of access to sensitive configuration files (e.g., CommServe database configuration, credential stores) at unexpected times or by unexpected processes.
  • Process: Anomalous CommServe service activity correlating with external network requests, particularly file read operations on system or configuration directories not normally accessed via the web interface.

Mitigation and workarounds

Commvault has released patched maintenance releases addressing this vulnerability. Customers should upgrade CommServe to version 11.36.123 or later (for the 11.36 branch), 11.40.72 or later (11.40 branch), 11.44.20 or later (11.44 branch), or 11.46.20 or later (11.46 branch). As a compensating control, organizations should implement network access controls to restrict access to CommServe systems to trusted hosts only, and monitor file access logs for path traversal patterns. Applying the principle of least privilege to service accounts and user permissions is also recommended (Commvault Advisory, GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Commvault vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77105HIGH8.7
  • Commvault logoCommvault
  • cpe:2.3:a:commvault:commvault
NoYesSep 08, 2026
CVE-2026-77103HIGH8.7
  • Commvault logoCommvault
  • cpe:2.3:a:commvault:commvault
NoYesSep 08, 2026
CVE-2026-77102HIGH8.7
  • Commvault logoCommvault
  • cpe:2.3:a:commvault:commvault
NoYesSep 08, 2026
CVE-2026-77104HIGH8.3
  • Commvault logoCommvault
  • cpe:2.3:a:commvault:commvault
NoYesSep 08, 2026
CVE-2026-77106HIGH7.7
  • Commvault logoCommvault
  • cpe:2.3:a:commvault:commvault
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management