Description
CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.
Published: 2026-09-08
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

CommServe’s cryptographic signature verification handling is flawed, permitting attackers to forge or modify signed requests and bypass legitimate privilege checks. This flaw can lead to an attacker acquiring higher privileges than allowed, enabling unauthorized actions or access to restricted resources.

Affected Systems

The vulnerability affects CommServe and Web Server components of the Commvault Cloud platform. Specific version information is not listed, so all releases lacking the maintenance update are considered vulnerable.

Risk and Exploitability

With a CVSS score of 8.7 the flaw is high‑severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves manipulating signed requests or tokens to bypass the normal privilege checks, potentially granting system‑level access.

Generated by OpenCVE AI on September 8, 2026 at 16:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest CommServe and Web Server maintenance release that fixes the cryptographic signature verification flaw.
  • Update any custom or third‑party integrations that rely on CommServe signatures to use the corrected signing process provided in the maintenance release.
  • Review and revoke any privileged tokens or account credentials that may have been exposed during the unpatched period, and generate new tokens with the updated signing configuration.

Generated by OpenCVE AI on September 8, 2026 at 16:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
Microsoft
Microsoft windows
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Commvault
Commvault commvault
Vendors & Products Commvault
Commvault commvault

Tue, 08 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-347
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Tue, 08 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.
Title CommServe Privilege Escalation
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Commvault Commvault
Linux Linux Kernel
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: Commvault

Published:

Updated: 2026-09-09T04:26:06.709Z

Reserved: 2026-08-20T10:58:02.223Z

Link: CVE-2026-77105

cve-icon Vulnrichment

Updated: 2026-09-08T13:26:08.417Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T13:17:26.393

Modified: 2026-09-09T15:52:59.420

Link: CVE-2026-77105

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:30:17Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-347

    Improper Verification of Cryptographic Signature