Junglewise Threat Intelligence

CVE-2026-77105: Commvault CommServe cryptographic signature verification in privilege management

CVE-2026-77105 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Commvault CommServe. Vendors: Commvault.

Executive brief

Commvault CommServe, a backup and disaster recovery management platform, contains a flaw in how it verifies cryptographic signatures used to control administrative access. An attacker who can interact with CommServe or its web server could exploit this to escalate privileges and gain unauthorized administrative control over the system, potentially compromising all protected data and operations.

Technical details

The vulnerability is a cryptographic signature verification issue in the CommServe privilege management subsystem. The flaw allows bypass or manipulation of signature verification checks that are intended to authenticate and authorize privileged operations. An attacker with network access to CommServe or its web server can exploit this to escalate privileges without requiring valid credentials. The attack vector appears to be network-based and does not require prior authentication. Commvault has released patched maintenance releases for affected versions (11.36.x, 11.40.x, 11.44.x, and 11.46.x tracks), and customers are advised to upgrade immediately.

Affected products

  • Commvault CommServe 11.36.0-11.36.122, 11.40.0-11.40.71, 11.44.0-11.44.19, 11.46.0-11.46.19
  • Commvault Web Server 11.36.0-11.36.122, 11.40.0-11.40.71, 11.44.0-11.44.19, 11.46.0-11.46.19

Timeline

  • 2026-09-08: disclosed

References

Related threats