Junglewise Threat Intelligence

CVE-2026-77091: Commvault DataCube path traversal in security feature enforcement

CVE-2026-77091 · Severity: high · CVSS 7.8 · Published 2026-09-08

Vendors: Commvault.

Executive brief

Commvault's DataCube is a data management and backup platform used by enterprises to protect and manage critical business data. A path traversal vulnerability allows attackers to bypass security controls that protect data access and compliance enforcement, potentially exposing sensitive information or allowing unauthorized operations without proper authorization checks.

Technical details

The vulnerability is a path traversal issue in Commvault DataCube that affects security feature enforcement. The attack vector is network-based, likely requiring authenticated access or ability to interact with affected components (Content Extractor and Index Store). By manipulating file paths, an attacker can circumvent security controls designed to enforce data access policies and compliance checks. The vulnerability impacts versions 11.46.0-11.46.19, 11.44.0-11.44.19, 11.40.0-11.40.71, and 11.36.0-11.36.122 across Linux and Windows platforms. Commvault has released patched versions (11.46.20+, 11.44.20+, 11.40.72+, and 11.36.123+) and recommends immediate upgrade.

Affected products

  • Commvault DataCube 11.36.0 through 11.46.19 (specific ranges: 11.36.0-11.36.122, 11.40.0-11.40.71, 11.44.0-11.44.19, 11.46.0-11.46.19)

Timeline

  • 2026-09-08: disclosed

References