Path Traversal Vulnerability in DataCube by Commvault
CVE-2026-77091
8.5HIGH
What is CVE-2026-77091?
DataCube from Commvault is affected by a path traversal vulnerability that compromises security feature enforcement. Attackers could exploit this issue to access restricted areas of the file system, leading to unauthorized data exposure. Users are strongly advised to upgrade to the latest resolved maintenance release to mitigate this risk. Ensuring Content Extractor and Index Store are updated is essential for maintaining system integrity.
Affected Version(s)
Commvault Cloud Windows 11.46.0 <= 11.46.19
Commvault Cloud Windows 11.44.0 <= 11.44.19
Commvault Cloud Windows 11.40.0 <= 11.40.71
References
CVSS V4
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michael Tucker and Tan Chew Keong from the XOR team at JPMorgan Chase.
