Description
CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
Published: 2026-09-08
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

CommServe contains a heap-based buffer overflow that can cause the service to crash, resulting in a denial of service that affects all users of the affected CommServe server. No code execution or data theft is implied by the description.

Affected Systems

The vulnerability affects Commvault Cloud's CommServe component; the advisory does not specify exact versions but recommends upgrading to the latest maintenance release. All customers running the affected CommServe should check their current release and apply the vendor‑supplied patch.

Risk and Exploitability

The CVSS score of 8.7 classifies this flaw as high severity, and the absence of an EPSS score suggests limited publicly available exploitation data. Based on the description, it is inferred that the vulnerability could potentially be exploited from outside the organization if the CommServe service is reachable over the network, although the description does not specify authentication requirements. As the flaw leads to a critical service disruption, it is prudent to treat this as a high‑risk condition.

Generated by OpenCVE AI on September 8, 2026 at 14:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest CommServe maintenance release that addresses the heap‑based buffer overflow.
  • If the patch cannot be applied immediately, restrict external access to the CommServe service to trusted internal IP ranges to reduce exposure.
  • Enable monitoring of CommServe process restarts or crashes to detect and respond to exploitation attempts promptly.

Generated by OpenCVE AI on September 8, 2026 at 14:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
Microsoft
Microsoft windows
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Commvault
Commvault commvault
Vendors & Products Commvault
Commvault commvault

Tue, 08 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
Title CommServe Denial of Service
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Commvault Commvault
Linux Linux Kernel
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: Commvault

Published:

Updated: 2026-09-08T13:25:21.705Z

Reserved: 2026-08-20T10:57:52.110Z

Link: CVE-2026-77102

cve-icon Vulnrichment

Updated: 2026-09-08T13:25:17.902Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T13:17:25.987

Modified: 2026-09-09T15:55:47.400

Link: CVE-2026-77102

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:30:17Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow