Description
CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
Published: 2026-09-08
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access and Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

CommServe has a flaw that allows an attacker to bypass authentication, which can be used to access data they should not see. The vulnerability is an authentication bypass that leads to information disclosure. It could enable an attacker to read restricted application data and potentially other system configuration details, compromising confidentiality and integrity of stored data. The inclusion of CWE‑288 suggests that the flaw may also result in information leakage or inadequate logging of the unauthorized access.

Affected Systems

The affected product is CommVault Cloud’s CommServe component. The advisory advises users to update to the latest maintenance release to address the issue. No specific version numbers are listed in the advisory.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, and the advisory notes that no EPSS score is available, so the exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting that it has not yet been widely exploited in the wild. The likely attack vector, based on the description, is a legitimate user authentication bypass that permits unauthorized access to the CommServe interface and the data it exposes.

Generated by OpenCVE AI on September 8, 2026 at 18:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update CommServe to the latest maintenance release as released by the vendor
  • Review and harden authentication and access controls on the affected platform
  • Monitor authentication logs for unusual activity.

Generated by OpenCVE AI on September 8, 2026 at 18:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
Microsoft
Microsoft windows
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Commvault
Commvault commvault
Vendors & Products Commvault
Commvault commvault

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-287

Tue, 08 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-288
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-287

Tue, 08 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
Title CommServe Information Disclosure
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Commvault Commvault
Linux Linux Kernel
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: Commvault

Published:

Updated: 2026-09-08T13:25:38.622Z

Reserved: 2026-08-20T10:57:52.110Z

Link: CVE-2026-77103

cve-icon Vulnrichment

Updated: 2026-09-08T13:25:35.362Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T13:17:26.140

Modified: 2026-09-09T15:56:34.583

Link: CVE-2026-77103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:30:17Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel