Path Traversal Vulnerability in CommServe by Commvault
CVE-2026-77104

8.3HIGH

Key Information:

Vendor

Commvault

Vendor
CVE Published:
8 September 2026

What is CVE-2026-77104?

A path traversal vulnerability in CommServe allows attackers to manipulate file paths, potentially disclosing sensitive information stored on the server. This issue may lead to unauthorized access to system files or configuration data. Commvault recommends that affected customers promptly upgrade to the latest maintenance release to mitigate this risk and protect their data integrity.

Affected Version(s)

Commvault Cloud Windows 11.46.0 <= 11.46.19

Commvault Cloud Windows 11.44.0 <= 11.44.19

Commvault Cloud Windows 11.40.0 <= 11.40.71

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Tucker and Tan Chew Keong from the XOR team at JPMorgan Chase.
.