8.8

CVE-2026-77106

Cvlaunchd Code Execution

Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Commvault ≫ Commvault Version >= 11.36.0 < 11.36.123
Commvault ≫ Commvault Version >= 11.40.0 < 11.40.72
Commvault ≫ Commvault Version >= 11.44.0 < 11.44.20
Commvault ≫ Commvault Version >= 11.46.0 < 11.46.20
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.185
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
050066fd-a2f9-4f32-ab5d-4c53f48bc333 7.7 0 0
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://documentation.commvault.com/securityadvisories/CV_2026_08_8.html
Vendor Advisory