Description
Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor.
Published: 2026-09-08
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in an unsafe deserialization routine within Commvault Content Extractor that allows untrusted data to be processed as executable code. This flaw can enable an attacker to inject malicious payloads that bypass normal privilege checks, effectively giving them escalated access on the target system. The weakness is characterized by the handling of deserialized objects, which directly compromises integrity and confidentiality of privileged operations.

Affected Systems

Affected vendors include Commvault, specifically the CommVault Cloud product line. No discrete product or version identifiers are listed, so any deployment of the Content Extractor component that remains on the original release is potentially vulnerable. Users should verify their deployment against the latest maintenance release noted in the advisory.

Risk and Exploitability

The CVSS base score of 7.3 indicates a high severity with significant impact. The EPSS score is not available, so the current exploitation probability is uncertain, but the absence of a KEV listing suggests no widely reported exploitation at this time. Attackers would typically need to supply a crafted payload to the vulnerable deserialization point, which requires either a user interaction or ability to influence the data stream. Until the fixed release is applied, the vulnerability could be exploited.

Generated by OpenCVE AI on September 8, 2026 at 13:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official maintenance release of Content Extractor as noted in the advisory
  • Ensure that all instances of the vulnerable component are updated to the patched version
  • If immediate patch deployment is not feasible, isolate the affected services and restrict external input to validated sources to mitigate deserialization risks

Generated by OpenCVE AI on September 8, 2026 at 13:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Tue, 08 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor.
Title Content Extractor Privilege Escalation
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Commvault

Published:

Updated: 2026-09-08T13:34:25.246Z

Reserved: 2026-08-20T10:56:58.070Z

Link: CVE-2026-77092

cve-icon Vulnrichment

Updated: 2026-09-08T13:34:11.351Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T13:17:25.480

Modified: 2026-09-08T14:17:27.013

Link: CVE-2026-77092

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T13:30:18Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data