CVE-2026-77092: unauthenticated deserialization in Commvault Commvault Cloud

An unauthenticated attacker can exploit a deserialization of untrusted data flaw in Commvault Cloud to impact privilege management and gain elevated control over the affected component. CVE-2026-77092 is a CWE-502 issue affecting Commvault Cloud releases in the 11.x line: 11.46.0–11.46.19, 11.44.0–11.44.19, 11.40.0–11.40.71 and 11.36.0–11.36.122. The vulnerability requires only the ability to reach the vulnerable service; no user interaction or credentials are listed in the available facts.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00323
CWE
CWE-502
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as high urgency: the flaw scores 9.8 and no fixes are published for the affected 11.x releases, so immediately reduce exposure and prepare to apply vendor updates when released.

What is CVE-2026-77092?

An unauthenticated attacker can exploit a deserialization of untrusted data flaw in Commvault Cloud to impact privilege management and gain elevated control over the affected component. CVE-2026-77092 is a CWE-502 issue affecting Commvault Cloud releases in the 11.x line: 11.46.0–11.46.19, 11.44.0–11.44.19, 11.40.0–11.40.71 and 11.36.0–11.36.122. The vulnerability requires only the ability to reach the vulnerable service; no user interaction or credentials are listed in the available facts. The weakness is classified as CWE-502 (Deserialization of Untrusted Data).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Commvault Commvault Cloud are affected?

BRANCHAFFECTEDFIXED
11.x11.46.0 – 11.46.19
11.x11.44.0 – 11.44.19
11.x11.40.0 – 11.40.71
11.x11.36.0 – 11.36.122

Is CVE-2026-77092 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-77092

  1. Restrict network access to Commvault Cloud management endpoints to trusted networks and VPNs.
  2. Implement strict firewall rules and isolate the affected service from internet exposure.
  3. Increase monitoring and logging for signs of unexpected privilege changes or deserialization-related errors.
  4. Follow Commvault guidance and apply official patches or maintenance releases as soon as they are published.

Frequently asked questions

Is CVE-2026-77092 being actively exploited?

There are no public reports of exploitation of CVE-2026-77092 as of 2026-09-30.

Which Commvault Cloud versions are affected by CVE-2026-77092?

Commvault Cloud releases in the 11.x line are affected: 11.46.0–11.46.19, 11.44.0–11.44.19, 11.40.0–11.40.71 and 11.36.0–11.36.122.

Is there a patch for CVE-2026-77092?

No fixed versions are listed for CVE-2026-77092 in the provided facts; Commvault has not published fixes for the affected 11.x releases in the data supplied.

Does CVE-2026-77092 require authentication?

The available information indicates the issue is a deserialization of untrusted data and does not list a need for authentication to exploit the vulnerability in Commvault Cloud.

References