CVE-2026-77105: CommServe Privilege Escalation
Published Sep 8, 2026
·Updated
CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.
Affected Software
8 affected components
CommServe
Web Server
All of the following
Any of the following
Commvault Commvault>=11.36.0<11.36.123
Commvault Commvault>=11.40.0<11.40.72
Commvault Commvault>=11.44.0<11.44.20
Commvault Commvault>=11.46.0<11.46.20
Any of the following
Linux Linux kernel
Microsoft Windows
Event History
Sep 8, 2026
CVE Published
via MITRE·12:12 PM
Data Sourced
via MITRE·12:12 PM
DescriptionWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Which components should be updated to address this issue?
Update both CommServe and the Web Server to the resolved maintenance release.
2
Is a workaround available if the maintenance release cannot be applied immediately?
The provided advisory information identifies upgrading to the resolved maintenance release as the remediation and does not specify an alternative workaround.