CVE-2026-77103
Analyzed Analyzed - Analysis Complete

Authentication Bypass in CommServe Leading to Information Disclosure

Vulnerability report for CVE-2026-77103, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-09

Assigner: Commvault

Description

CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
commvault commvault From 11.36.0 (inc) to 11.36.123 (exc)
commvault commvault From 11.40.0 (inc) to 11.40.72 (exc)
commvault commvault From 11.44.0 (inc) to 11.44.20 (exc)
commvault commvault From 11.46.0 (inc) to 11.46.20 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-288 The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CommServe had an authentication bypass issue that allowed unauthorized access and information disclosure. This means attackers could bypass normal authentication to gain access to sensitive data or systems without proper credentials.

Detection Guidance

To detect this vulnerability, check if your CommServe software version falls between 11.36.0 and 11.46.19. Log into the Command Center, go to the Servers section, filter by relevant roles, and verify if all servers are updated to version 11.36.20, 11.40.72, 11.44.20, or 11.46.20 or higher.

Impact Analysis

This vulnerability could allow attackers to access sensitive information or perform unauthorized actions on affected systems. It may lead to data breaches, system compromise, or further network infiltration depending on the attacker's goals.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating compliance requirements under GDPR, HIPAA, or other regulations. Organizations may face legal penalties, fines, or reputational damage if data is exposed due to this issue.

Mitigation Strategies

Immediately upgrade CommServe to version 11.36.20, 11.40.72, 11.44.20, or 11.46.20 or higher to resolve the authentication bypass issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77103. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart