Junglewise Threat Intelligence

CVE-2026-77103: Commvault CommServe authentication bypass

CVE-2026-77103 · Severity: high · CVSS 7.5 · Published 2026-09-08

Technologies: Commvault CommServe. Vendors: Commvault.

Executive brief

Commvault CommServe, a centralized data management and backup platform, contains an authentication bypass flaw that allows attackers to bypass access controls and access sensitive information without proper authorization. Exploitation could lead to unauthorized access to backup data, system configuration, and other sensitive assets managed by the platform.

Technical details

The vulnerability is an authentication bypass issue in CommServe affecting access authorization and information disclosure. An attacker can exploit this flaw to bypass authentication mechanisms and gain unauthorized access to the system without valid credentials. The affected versions range from 11.36.0 to 11.46.19 across Linux and Windows platforms. Patches are available in versions 11.36.123, 11.40.72, 11.44.20, and 11.46.20 and higher. Users should upgrade to the resolved maintenance releases immediately.

Affected products

  • Commvault CommServe 11.36.0-11.36.122, 11.40.0-11.40.71, 11.44.0-11.44.19, 11.46.0-11.46.19

Timeline

  • 2026-09-08: disclosed: Commvault security advisory CV_2026_08_5 published
  • 2026-09-08: patched: Resolved versions available: 11.36.123, 11.40.72, 11.44.20, 11.46.20 and higher

References

Related threats