Authorization Issue in Commvault's Cvlaunchd Affects Command Execution
CVE-2026-77106

7.7HIGH

Key Information:

Vendor

Commvault

Vendor
CVE Published:
8 September 2026

What is CVE-2026-77106?

The Cvlaunchd component in Commvault software has a flaw that allows for unauthorized command execution due to a missing authorization check. This could potentially allow malicious actors to perform actions without proper permissions. Users are strongly advised to upgrade to the latest resolved maintenance release to safeguard their installations, including Commserve, Webserver, Command Center, Media Agents, Clients, and HyperScale X.

Affected Version(s)

Commvault Cloud Windows 11.46.0 <= 11.46.19

Commvault Cloud Windows 11.44.0 <= 11.44.19

Commvault Cloud Windows 11.40.0 <= 11.40.71

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.