CVE-2026-77103: CommServe Information Disclosure
Published Sep 8, 2026
·Updated
CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
Affected Software
7 affected components
CommServe
All of the following
Any of the following
Commvault Commvault>=11.36.0<11.36.123
Commvault Commvault>=11.40.0<11.40.72
Commvault Commvault>=11.44.0<11.44.20
Commvault Commvault>=11.46.0<11.46.20
Any of the following
Linux Linux kernel
Microsoft Windows
Event History
Sep 8, 2026
CVE Published
via MITRE·12:12 PM
Data Sourced
via MITRE·12:12 PM
DescriptionWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What should customers do to remediate this issue?
Upgrade CommServe to the resolved maintenance release identified by the vendor advisory. The available information does not identify a workaround or mitigation for systems that cannot yet be upgraded.
2
What security impact is identified?
The issue is an authentication bypass affecting access authorization and may result in information disclosure. The provided information does not specify the required attacker access, affected versions, or exploitation conditions.