Path Traversal Vulnerability in DataCube by Commvault
CVE-2026-77091

8.5HIGH

Key Information:

Vendor

Commvault

Vendor
CVE Published:
8 September 2026

What is CVE-2026-77091?

DataCube from Commvault is affected by a path traversal vulnerability that compromises security feature enforcement. Attackers could exploit this issue to access restricted areas of the file system, leading to unauthorized data exposure. Users are strongly advised to upgrade to the latest resolved maintenance release to mitigate this risk. Ensuring Content Extractor and Index Store are updated is essential for maintaining system integrity.

Affected Version(s)

Commvault Cloud Windows 11.46.0 <= 11.46.19

Commvault Cloud Windows 11.44.0 <= 11.44.19

Commvault Cloud Windows 11.40.0 <= 11.40.71

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Tucker and Tan Chew Keong from the XOR team at JPMorgan Chase.
.