CVE-2026-77091

Summary

DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and Index Store.

Affected Software

VendorProductVersion RangeStatus
CommvaultCommvault Cloud11.46.0 <= 11.46.19affected
CommvaultCommvault Cloud11.44.0 <= 11.44.19affected
CommvaultCommvault Cloud11.40.0 <= 11.40.71affected
CommvaultCommvault Cloud11.36.0 <= 11.36.122affected

Weaknesses

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References