Path Traversal Vulnerability in CommServe by Commvault
CVE-2026-77104
8.3HIGH
What is CVE-2026-77104?
A path traversal vulnerability in CommServe allows attackers to manipulate file paths, potentially disclosing sensitive information stored on the server. This issue may lead to unauthorized access to system files or configuration data. Commvault recommends that affected customers promptly upgrade to the latest maintenance release to mitigate this risk and protect their data integrity.
Affected Version(s)
Commvault Cloud Windows 11.46.0 <= 11.46.19
Commvault Cloud Windows 11.44.0 <= 11.44.19
Commvault Cloud Windows 11.40.0 <= 11.40.71
References
CVSS V4
Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michael Tucker and Tan Chew Keong from the XOR team at JPMorgan Chase.
