CVE-2026-77106: Cvlaunchd Code Execution
Published Sep 8, 2026
·Updated
Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
Affected Software
5 affected components
Commvault cvlaunchd
Commvault Commvault>=11.36.0<11.36.123
Commvault Commvault>=11.40.0<11.40.72
Commvault Commvault>=11.44.0<11.44.20
Commvault Commvault>=11.46.0<11.46.20
Event History
Sep 8, 2026
CVE Published
via MITRE·12:12 PM
Data Sourced
via MITRE·12:12 PM
DescriptionWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Which parts of a Commvault deployment should be updated?
Update all Commvault installations, including CommServe, Webserver, Command Center, Media Agents, Clients, and HyperScale X.
2
What is the recommended remediation?
Upgrade software customers to the resolved maintenance release.
3
What authorization weakness is involved?
The issue is a missing authorization control affecting command execution authorization.