Description
CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
Published: 2026-09-08
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

CommServe contains a path traversal flaw that permits an attacker to construct file paths that escape the intended directory boundaries and retrieve arbitrary files from the underlying operating system. The flaw is triggered when malicious path components are included in requests handled by the CommServe web interface or API. This enables the disclosure of sensitive system files, configuration data, or deployment artifacts, compromising the confidentiality of the infrastructure. The weakness is aligned with CWE-22 Path Traversal. Based on the description, the likely attack vector is through the CommServe web interface or API that accepts file path parameters.

Affected Systems

Customers who run the Commvault Cloud CommServe component are impacted. The advisory does not specify a version range; it simply recommends upgrading to the latest maintenance release that incorporates the fix. No other product or firmware versions are explicitly mentioned.

Risk and Exploitability

The vulnerability scores a CVSS of 8.3, reflecting high potential for information disclosure. EPSS data is not available, and the flaw is not listed in the CISA known exploited vulnerabilities catalog, indicating no confirmed exploitation to date. Assuming an attacker can reach the CommServe instance over the network, the path traversal can be triggered without special privileges and may allow the reading of arbitrary files, providing a covert channel for stealing sensitive data. Based on the description, the likely attack vector is remote access to CommServe over the network. The remediation urgency is therefore high, especially for services exposed to untrusted networks.

Generated by OpenCVE AI on September 8, 2026 at 14:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade CommServe to the latest maintenance release that contains the fix.
  • Restrict access to the CommServe interface to authorized users only and isolate the service with network segmentation to limit exposure.
  • If upgrading is delayed, configure a web application firewall or firewall rules to reject any request containing path components that attempt directory traversal, such as ".." sequences.

Generated by OpenCVE AI on September 8, 2026 at 14:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
Microsoft
Microsoft windows
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Commvault
Commvault commvault
Vendors & Products Commvault
Commvault commvault

Tue, 08 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
Title CommServe Path Traversal
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Commvault Commvault
Linux Linux Kernel
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: Commvault

Published:

Updated: 2026-09-08T13:25:55.269Z

Reserved: 2026-08-20T10:57:52.110Z

Link: CVE-2026-77104

cve-icon Vulnrichment

Updated: 2026-09-08T13:25:51.582Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T13:17:26.270

Modified: 2026-09-09T15:57:00.180

Link: CVE-2026-77104

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:30:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')