Description
DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and Index Store.
Published: 2026-09-08
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Security feature bypass with potential for unauthorized data access
Action: Apply patch
AI Analysis

Impact

A path traversal flaw in the DataCube component allows an attacker to subvert the security feature that governs data access. This weakness permits manipulation of file paths used by the system, enabling the attacker to read or modify files outside the intended working directory and circumvent built‑in safeguards. The vulnerability could lead to unauthorized disclosure or alteration of sensitive data, thereby compromising confidentiality and integrity of the environment.

Affected Systems

Affected devices run the Commvault Cloud system, specifically the DataCube component. The component is impacted by the path traversal issue and requires an update to the latest maintenance release.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, probably via a payload that crafts an out‑of‑bounds path in a request to the DataCube service.

Generated by OpenCVE AI on September 8, 2026 at 16:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the resolved maintenance release of DataCube, which includes a fix that patches the path traversal logic.
  • Upgrade the Content Extractor and Index Store components to the supported versions that enforce strict path validation; these are part of the patch bundle.
  • If an update cannot be applied immediately, restrict incoming file path inputs by validating against a whitelist or normalizing the path before processing to mitigate traversal attempts.

Generated by OpenCVE AI on September 8, 2026 at 16:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Commvault
Commvault commvault
Vendors & Products Commvault
Commvault commvault

Tue, 08 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and Index Store.
Title DataCube Security Feature Bypass
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Commvault Commvault
cve-icon MITRE

Status: PUBLISHED

Assigner: Commvault

Published:

Updated: 2026-09-08T13:33:54.236Z

Reserved: 2026-08-20T10:56:58.070Z

Link: CVE-2026-77091

cve-icon Vulnrichment

Updated: 2026-09-08T13:33:47.846Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T13:17:25.357

Modified: 2026-09-11T14:24:13.410

Link: CVE-2026-77091

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:30:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')