Search

Find a vulnerability

Search criteria

    30 vulnerabilities by Commvault

    CVE-2026-77106 (GCVE-0-2026-77106)

    Vulnerability from cvelistv5 – Published: 2026-09-08 12:12 – Updated: 2026-09-09 04:26
    VLAI
    Title
    Cvlaunchd Code Execution
    Summary
    Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-08 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    Commvault Commvault Cloud Affected: 11.46.0 , ≤ 11.46.19 (custom)
    Affected: 11.44.0 , ≤ 11.44.19 (custom)
    Affected: 11.40.0 , ≤ 11.40.71 (custom)
    Affected: 11.36.0 , ≤ 11.36.122 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77106",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-08T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-862",
                    "description": "CWE-862 Missing Authorization",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-09T04:26:08.110Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Windows",
                "Linux"
              ],
              "product": "Commvault Cloud",
              "vendor": "Commvault",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "11.46.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.46.19",
                  "status": "affected",
                  "version": "11.46.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.44.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.44.19",
                  "status": "affected",
                  "version": "11.44.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.40.72",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.40.71",
                  "status": "affected",
                  "version": "11.40.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.36.123",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.36.122",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 7.7,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-862: Missing Authorization",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-08T12:15:44.123Z",
            "orgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
            "shortName": "Commvault"
          },
          "references": [
            {
              "url": "https://documentation.commvault.com/securityadvisories/CV_2026_08_8.html"
            }
          ],
          "title": "Cvlaunchd Code Execution"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
        "assignerShortName": "Commvault",
        "cveId": "CVE-2026-77106",
        "datePublished": "2026-09-08T12:12:55.097Z",
        "dateReserved": "2026-08-20T10:58:04.239Z",
        "dateUpdated": "2026-09-09T04:26:08.110Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77105 (GCVE-0-2026-77105)

    Vulnerability from cvelistv5 – Published: 2026-09-08 12:12 – Updated: 2026-09-09 04:26
    VLAI
    Title
    CommServe Privilege Escalation
    Summary
    CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-08 00:00 UTC
    CWE
    • CWE-347 - Improper Verification of Cryptographic Signature
    Impacted products
    Vendor Product Version
    Commvault Commvault Cloud Affected: 11.46.0 , ≤ 11.46.19 (custom)
    Affected: 11.44.0 , ≤ 11.44.19 (custom)
    Affected: 11.40.0 , ≤ 11.40.71 (custom)
    Affected: 11.36.0 , ≤ 11.36.122 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77105",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-08T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-347",
                    "description": "CWE-347 Improper Verification of Cryptographic Signature",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-09T04:26:06.709Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Windows",
                "Linux"
              ],
              "product": "Commvault Cloud",
              "vendor": "Commvault",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "11.46.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.46.19",
                  "status": "affected",
                  "version": "11.46.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.44.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.44.19",
                  "status": "affected",
                  "version": "11.44.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.40.72",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.40.71",
                  "status": "affected",
                  "version": "11.40.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.36.123",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.36.122",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Michael Tucker and Tan Chew Keong from the XOR team at JPMorgan Chase."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-347: Improper Verification of Cryptographic Signature",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-08T12:12:54.826Z",
            "orgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
            "shortName": "Commvault"
          },
          "references": [
            {
              "url": "https://documentation.commvault.com/securityadvisories/CV_2026_08_7.html"
            }
          ],
          "title": "CommServe Privilege Escalation"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
        "assignerShortName": "Commvault",
        "cveId": "CVE-2026-77105",
        "datePublished": "2026-09-08T12:12:54.826Z",
        "dateReserved": "2026-08-20T10:58:02.223Z",
        "dateUpdated": "2026-09-09T04:26:06.709Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77104 (GCVE-0-2026-77104)

    Vulnerability from cvelistv5 – Published: 2026-09-08 12:12 – Updated: 2026-09-08 13:25
    VLAI
    Title
    CommServe Path Traversal
    Summary
    CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-08 13:23 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    Commvault Commvault Cloud Affected: 11.46.0 , ≤ 11.46.19 (custom)
    Affected: 11.44.0 , ≤ 11.44.19 (custom)
    Affected: 11.40.0 , ≤ 11.40.71 (custom)
    Affected: 11.36.0 , ≤ 11.36.122 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77104",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-08T13:23:30.381204Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-22",
                    "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-08T13:25:55.269Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Windows",
                "Linux"
              ],
              "product": "Commvault Cloud",
              "vendor": "Commvault",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "11.46.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.46.19",
                  "status": "affected",
                  "version": "11.46.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.44.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.44.19",
                  "status": "affected",
                  "version": "11.44.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.40.72",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.40.71",
                  "status": "affected",
                  "version": "11.40.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.36.123",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.36.122",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Michael Tucker and Tan Chew Keong from the XOR team at JPMorgan Chase."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-08T12:12:54.620Z",
            "orgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
            "shortName": "Commvault"
          },
          "references": [
            {
              "url": "https://documentation.commvault.com/securityadvisories/CV_2026_08_6.html"
            }
          ],
          "title": "CommServe Path Traversal"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
        "assignerShortName": "Commvault",
        "cveId": "CVE-2026-77104",
        "datePublished": "2026-09-08T12:12:54.620Z",
        "dateReserved": "2026-08-20T10:57:52.110Z",
        "dateUpdated": "2026-09-08T13:25:55.269Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77103 (GCVE-0-2026-77103)

    Vulnerability from cvelistv5 – Published: 2026-09-08 12:12 – Updated: 2026-09-08 13:25
    VLAI
    Title
    CommServe Information Disclosure
    Summary
    CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-08 13:23 UTC
    CWE
    • CWE-288 - Authentication Bypass Using an Alternate Path or Channel
    Impacted products
    Vendor Product Version
    Commvault Commvault Cloud Affected: 11.46.0 , ≤ 11.46.19 (custom)
    Affected: 11.44.0 , ≤ 11.44.19 (custom)
    Affected: 11.40.0 , ≤ 11.40.71 (custom)
    Affected: 11.36.0 , ≤ 11.36.122 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77103",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-08T13:23:49.319206Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-288",
                    "description": "CWE-288 Authentication Bypass Using an Alternate Path or Channel",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-08T13:25:38.622Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Windows",
                "Linux"
              ],
              "product": "Commvault Cloud",
              "vendor": "Commvault",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "11.46.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.46.19",
                  "status": "affected",
                  "version": "11.46.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.44.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.44.19",
                  "status": "affected",
                  "version": "11.44.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.40.72",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.40.71",
                  "status": "affected",
                  "version": "11.40.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.36.123",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.36.122",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Michael Tucker and Tan Chew Keong from the XOR team at JPMorgan Chase."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-288: Authentication Bypass Using an Alternate Path or Channel",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-08T12:12:54.437Z",
            "orgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
            "shortName": "Commvault"
          },
          "references": [
            {
              "url": "https://documentation.commvault.com/securityadvisories/CV_2026_08_5.html"
            }
          ],
          "title": "CommServe Information Disclosure"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
        "assignerShortName": "Commvault",
        "cveId": "CVE-2026-77103",
        "datePublished": "2026-09-08T12:12:54.437Z",
        "dateReserved": "2026-08-20T10:57:52.110Z",
        "dateUpdated": "2026-09-08T13:25:38.622Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77102 (GCVE-0-2026-77102)

    Vulnerability from cvelistv5 – Published: 2026-09-08 12:12 – Updated: 2026-09-08 13:25
    VLAI
    Title
    CommServe Denial of Service
    Summary
    CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-08 13:24 UTC
    CWE
    • CWE-122 - Heap-based Buffer Overflow
    Impacted products
    Vendor Product Version
    Commvault Commvault Cloud Affected: 11.46.0 , ≤ 11.46.19 (custom)
    Affected: 11.44.0 , ≤ 11.44.19 (custom)
    Affected: 11.40.0 , ≤ 11.40.71 (custom)
    Affected: 11.36.0 , ≤ 11.36.122 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77102",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-08T13:24:19.978501Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-122",
                    "description": "CWE-122 Heap-based Buffer Overflow",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-08T13:25:21.705Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Windows",
                "Linux"
              ],
              "product": "Commvault Cloud",
              "vendor": "Commvault",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "11.46.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.46.19",
                  "status": "affected",
                  "version": "11.46.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.44.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.44.19",
                  "status": "affected",
                  "version": "11.44.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.40.72",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.40.71",
                  "status": "affected",
                  "version": "11.40.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.36.123",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.36.122",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Michael Tucker and Tan Chew Keong from the XOR team at JPMorgan Chase."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-122: Heap-based Buffer Overflow",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-08T12:12:54.281Z",
            "orgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
            "shortName": "Commvault"
          },
          "references": [
            {
              "url": "https://documentation.commvault.com/securityadvisories/CV_2026_08_4.html"
            }
          ],
          "title": "CommServe Denial of Service"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
        "assignerShortName": "Commvault",
        "cveId": "CVE-2026-77102",
        "datePublished": "2026-09-08T12:12:54.281Z",
        "dateReserved": "2026-08-20T10:57:52.110Z",
        "dateUpdated": "2026-09-08T13:25:21.705Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77101 (GCVE-0-2026-77101)

    Vulnerability from cvelistv5 – Published: 2026-09-08 12:12 – Updated: 2026-09-08 13:24
    VLAI
    Title
    CommServe Stack-based Buffer Overflow
    Summary
    CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-08 13:24 UTC
    CWE
    • CWE-121 - Stack-based Buffer Overflow
    Impacted products
    Vendor Product Version
    Commvault Commvault Cloud Affected: 11.46.0 , ≤ 11.46.19 (custom)
    Affected: 11.44.0 , ≤ 11.44.19 (custom)
    Affected: 11.40.0 , ≤ 11.40.71 (custom)
    Affected: 11.36.0 , ≤ 11.36.122 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77101",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-08T13:24:30.911215Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-121",
                    "description": "CWE-121 Stack-based Buffer Overflow",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-08T13:24:56.965Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Windows",
                "Linux"
              ],
              "product": "Commvault Cloud",
              "vendor": "Commvault",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "11.46.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.46.19",
                  "status": "affected",
                  "version": "11.46.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.44.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.44.19",
                  "status": "affected",
                  "version": "11.44.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.40.72",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.40.71",
                  "status": "affected",
                  "version": "11.40.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.36.123",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.36.122",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Michael Tucker and Tan Chew Keong from the XOR team at JPMorgan Chase."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-121: Stack-based Buffer Overflow",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-08T12:12:54.122Z",
            "orgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
            "shortName": "Commvault"
          },
          "references": [
            {
              "url": "https://documentation.commvault.com/securityadvisories/CV_2026_08_3.html"
            }
          ],
          "title": "CommServe Stack-based Buffer Overflow"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
        "assignerShortName": "Commvault",
        "cveId": "CVE-2026-77101",
        "datePublished": "2026-09-08T12:12:54.122Z",
        "dateReserved": "2026-08-20T10:57:52.110Z",
        "dateUpdated": "2026-09-08T13:24:56.965Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77098 (GCVE-0-2026-77098)

    Vulnerability from cvelistv5 – Published: 2026-09-08 12:12 – Updated: 2026-09-08 13:27
    VLAI
    Title
    Private Metrics Server SQL Injection
    Summary
    Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-08 13:27 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    Impacted products
    Vendor Product Version
    Commvault Commvault Cloud Affected: 11.46.0 , ≤ 11.46.19 (custom)
    Affected: 11.44.0 , ≤ 11.44.19 (custom)
    Affected: 11.40.0 , ≤ 11.40.71 (custom)
    Affected: 11.36.0 , ≤ 11.36.122 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77098",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-08T13:27:02.935632Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-89",
                    "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-08T13:27:30.322Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Windows",
                "Linux"
              ],
              "product": "Commvault Cloud",
              "vendor": "Commvault",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "11.46.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.46.19",
                  "status": "affected",
                  "version": "11.46.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.44.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.44.19",
                  "status": "affected",
                  "version": "11.44.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.40.72",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.40.71",
                  "status": "affected",
                  "version": "11.40.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.36.123",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.36.122",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Michael Tucker and Tan Chew Keong from the XOR team at JPMorgan Chase."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-89: Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-08T12:12:53.928Z",
            "orgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
            "shortName": "Commvault"
          },
          "references": [
            {
              "url": "https://documentation.commvault.com/securityadvisories/CV_2026_08_2.html"
            }
          ],
          "title": "Private Metrics Server SQL Injection"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
        "assignerShortName": "Commvault",
        "cveId": "CVE-2026-77098",
        "datePublished": "2026-09-08T12:12:53.928Z",
        "dateReserved": "2026-08-20T10:56:58.071Z",
        "dateUpdated": "2026-09-08T13:27:30.322Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77097 (GCVE-0-2026-77097)

    Vulnerability from cvelistv5 – Published: 2026-09-08 12:12 – Updated: 2026-09-08 13:30
    VLAI
    Title
    Private Metrics Server Denial of Service
    Summary
    Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-08 13:30 UTC
    CWE
    • CWE-306 - Missing Authentication for Critical Function
    Impacted products
    Vendor Product Version
    Commvault Commvault Cloud Affected: 11.46.0 , ≤ 11.46.19 (custom)
    Affected: 11.44.0 , ≤ 11.44.19 (custom)
    Affected: 11.40.0 , ≤ 11.40.71 (custom)
    Affected: 11.36.0 , ≤ 11.36.122 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77097",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-08T13:30:12.896266Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-306",
                    "description": "CWE-306 Missing Authentication for Critical Function",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-08T13:30:17.822Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Windows",
                "Linux"
              ],
              "product": "Commvault Cloud",
              "vendor": "Commvault",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "11.46.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.46.19",
                  "status": "affected",
                  "version": "11.46.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.44.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.44.19",
                  "status": "affected",
                  "version": "11.44.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.40.72",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.40.71",
                  "status": "affected",
                  "version": "11.40.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.36.123",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.36.122",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Michael Tucker and Tan Chew Keong from the XOR team at JPMorgan Chase."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved maintenance release. Update Private Metrics Server."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-306: Missing Authentication for Critical Function",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-08T12:12:53.765Z",
            "orgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
            "shortName": "Commvault"
          },
          "references": [
            {
              "url": "https://documentation.commvault.com/securityadvisories/CV_2026_08_1.html"
            }
          ],
          "title": "Private Metrics Server Denial of Service"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
        "assignerShortName": "Commvault",
        "cveId": "CVE-2026-77097",
        "datePublished": "2026-09-08T12:12:53.765Z",
        "dateReserved": "2026-08-20T10:56:58.071Z",
        "dateUpdated": "2026-09-08T13:30:17.822Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77092 (GCVE-0-2026-77092)

    Vulnerability from cvelistv5 – Published: 2026-09-08 12:12 – Updated: 2026-09-08 13:34
    VLAI
    Title
    Content Extractor Privilege Escalation
    Summary
    Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-08 13:34 UTC
    CWE
    • CWE-502 - Deserialization of Untrusted Data
    Impacted products
    Vendor Product Version
    Commvault Commvault Cloud Affected: 11.46.0 , ≤ 11.46.19 (custom)
    Affected: 11.44.0 , ≤ 11.44.19 (custom)
    Affected: 11.40.0 , ≤ 11.40.71 (custom)
    Affected: 11.36.0 , ≤ 11.36.122 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77092",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-08T13:34:22.105440Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-502",
                    "description": "CWE-502 Deserialization of Untrusted Data",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-08T13:34:25.246Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Windows",
                "Linux"
              ],
              "product": "Commvault Cloud",
              "vendor": "Commvault",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "11.46.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.46.19",
                  "status": "affected",
                  "version": "11.46.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.44.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.44.19",
                  "status": "affected",
                  "version": "11.44.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.40.72",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.40.71",
                  "status": "affected",
                  "version": "11.40.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.36.123",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.36.122",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Michael Tucker and Tan Chew Keong from the XOR team at JPMorgan Chase."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-502: Deserialization of Untrusted Data",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-08T12:12:53.589Z",
            "orgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
            "shortName": "Commvault"
          },
          "references": [
            {
              "url": "https://documentation.commvault.com/securityadvisories/CV_2026_07_6.html"
            }
          ],
          "title": "Content Extractor Privilege Escalation"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
        "assignerShortName": "Commvault",
        "cveId": "CVE-2026-77092",
        "datePublished": "2026-09-08T12:12:53.589Z",
        "dateReserved": "2026-08-20T10:56:58.070Z",
        "dateUpdated": "2026-09-08T13:34:25.246Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77091 (GCVE-0-2026-77091)

    Vulnerability from cvelistv5 – Published: 2026-09-08 12:12 – Updated: 2026-09-08 13:33
    VLAI
    Title
    DataCube Security Feature Bypass
    Summary
    DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and Index Store.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-08 13:33 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    Commvault Commvault Cloud Affected: 11.46.0 , ≤ 11.46.19 (custom)
    Affected: 11.44.0 , ≤ 11.44.19 (custom)
    Affected: 11.40.0 , ≤ 11.40.71 (custom)
    Affected: 11.36.0 , ≤ 11.36.122 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77091",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-08T13:33:48.703147Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-22",
                    "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-08T13:33:54.236Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Windows",
                "Linux"
              ],
              "product": "Commvault Cloud",
              "vendor": "Commvault",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "11.46.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.46.19",
                  "status": "affected",
                  "version": "11.46.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.44.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.44.19",
                  "status": "affected",
                  "version": "11.44.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.40.72",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.40.71",
                  "status": "affected",
                  "version": "11.40.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.36.123",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.36.122",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Michael Tucker and Tan Chew Keong from the XOR team at JPMorgan Chase."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and Index Store."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-08T12:12:53.432Z",
            "orgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
            "shortName": "Commvault"
          },
          "references": [
            {
              "url": "https://documentation.commvault.com/securityadvisories/CV_2026_07_3.html"
            }
          ],
          "title": "DataCube Security Feature Bypass"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
        "assignerShortName": "Commvault",
        "cveId": "CVE-2026-77091",
        "datePublished": "2026-09-08T12:12:53.432Z",
        "dateReserved": "2026-08-20T10:56:58.070Z",
        "dateUpdated": "2026-09-08T13:33:54.236Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77089 (GCVE-0-2026-77089)

    Vulnerability from cvelistv5 – Published: 2026-09-08 12:12 – Updated: 2026-09-09 12:34
    VLAI
    Title
    Command Center API Authentication Bypass
    Summary
    Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-09 04:26 UTC
    CWE
    • CWE-290 - Authentication Bypass by Spoofing
    Impacted products
    Vendor Product Version
    Commvault Commvault Cloud Affected: 11.46.0 , ≤ 11.46.19 (custom)
    Affected: 11.44.0 , ≤ 11.44.19 (custom)
    Affected: 11.40.0 , ≤ 11.40.71 (custom)
    Affected: 11.36.0 , ≤ 11.36.122 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77089",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-09T04:26:06.353164Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-290",
                    "description": "CWE-290 Authentication Bypass by Spoofing",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-09T12:34:01.813Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Windows",
                "Linux"
              ],
              "product": "Commvault Cloud",
              "vendor": "Commvault",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "11.46.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.46.19",
                  "status": "affected",
                  "version": "11.46.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.44.20",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.44.19",
                  "status": "affected",
                  "version": "11.44.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.40.72",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.40.71",
                  "status": "affected",
                  "version": "11.40.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.36.123",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.36.122",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Michael Tucker and Tan Chew Keong from the XOR team at JPMorgan Chase."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-290: Authentication Bypass by Spoofing",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-08T12:12:53.236Z",
            "orgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
            "shortName": "Commvault"
          },
          "references": [
            {
              "url": "https://documentation.commvault.com/securityadvisories/CV_2026_07_1.html"
            }
          ],
          "title": "Command Center API Authentication Bypass"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
        "assignerShortName": "Commvault",
        "cveId": "CVE-2026-77089",
        "datePublished": "2026-09-08T12:12:53.236Z",
        "dateReserved": "2026-08-20T10:56:18.889Z",
        "dateUpdated": "2026-09-09T12:34:01.813Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-13738 (GCVE-0-2026-13738)

    Vulnerability from cvelistv5 – Published: 2026-08-11 11:01 – Updated: 2026-08-11 16:48
    VLAI
    Title
    Improper Authorization Validation
    Summary
    CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-11 16:48 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    Commvault Commvault Cloud Affected: 11.46.0 , ≤ 11.46.9 (custom)
    Affected: 11.44.0 , ≤ 11.44.10 (custom)
    Affected: 11.40.0 , ≤ 11.40.62 (custom)
    Affected: 11.36.0 , ≤ 11.36.113 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-13738",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-11T16:48:09.726861Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-863",
                    "description": "CWE-863 Incorrect Authorization",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-11T16:48:34.748Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Windows",
                "Linux"
              ],
              "product": "Commvault Cloud",
              "vendor": "Commvault",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "11.46.10",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.46.9",
                  "status": "affected",
                  "version": "11.46.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.44.11",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.44.10",
                  "status": "affected",
                  "version": "11.44.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.40.63",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.40.62",
                  "status": "affected",
                  "version": "11.40.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.36.114",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.36.113",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations.  Software customers upgrade to resolved maintenance release.  Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 9.2,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-863: Incorrect Authorization",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-11T11:01:39.248Z",
            "orgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
            "shortName": "Commvault"
          },
          "references": [
            {
              "url": "https://documentation.commvault.com/securityadvisories/CV_2026_07_9.html"
            }
          ],
          "title": "Improper Authorization Validation"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
        "assignerShortName": "Commvault",
        "cveId": "CVE-2026-13738",
        "datePublished": "2026-08-11T11:01:39.248Z",
        "dateReserved": "2026-06-29T14:54:16.684Z",
        "dateUpdated": "2026-08-11T16:48:34.748Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-13737 (GCVE-0-2026-13737)

    Vulnerability from cvelistv5 – Published: 2026-08-11 11:01 – Updated: 2026-08-11 16:49
    VLAI
    Title
    Command Restriction Bypass
    Summary
    CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-11 16:48 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    Commvault Commvault Cloud Affected: 11.46.0 , ≤ 11.46.9 (custom)
    Affected: 11.44.0 , ≤ 11.44.10 (custom)
    Affected: 11.40.0 , ≤ 11.40.62 (custom)
    Affected: 11.36.0 , ≤ 11.36.113 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-13737",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-11T16:48:52.032563Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-863",
                    "description": "CWE-863 Incorrect Authorization",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-11T16:49:09.354Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Windows",
                "Linux"
              ],
              "product": "Commvault Cloud",
              "vendor": "Commvault",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "11.46.10",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.46.9",
                  "status": "affected",
                  "version": "11.46.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.44.11",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.44.10",
                  "status": "affected",
                  "version": "11.44.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.40.63",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.40.62",
                  "status": "affected",
                  "version": "11.40.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.36.114",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.36.113",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CommServe contained an allowlist bypass vulnerability affecting command execution authorization.  Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 9.2,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-863: Incorrect Authorization",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-11T11:01:38.785Z",
            "orgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
            "shortName": "Commvault"
          },
          "references": [
            {
              "url": "https://documentation.commvault.com/securityadvisories/CV_2026_07_8.html"
            }
          ],
          "title": "Command Restriction Bypass"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
        "assignerShortName": "Commvault",
        "cveId": "CVE-2026-13737",
        "datePublished": "2026-08-11T11:01:38.785Z",
        "dateReserved": "2026-06-29T14:54:15.451Z",
        "dateUpdated": "2026-08-11T16:49:09.354Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-13739 (GCVE-0-2026-13739)

    Vulnerability from cvelistv5 – Published: 2026-08-11 11:01 – Updated: 2026-08-11 14:13
    VLAI
    Title
    Server-Side Request Forgery (SSRF)
    Summary
    A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-11 14:13 UTC
    CWE
    • CWE-918 - Server-Side Request Forgery (SSRF)
    Impacted products
    Vendor Product Version
    Commvault Commvault Cloud Affected: 11.46.0 , ≤ 11.46.9 (custom)
    Affected: 11.44.0 , ≤ 11.44.10 (custom)
    Affected: 11.40.0 , ≤ 11.40.62 (custom)
    Affected: 11.36.0 , ≤ 11.36.113 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-13739",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-11T14:13:11.777885Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-918",
                    "description": "CWE-918 Server-Side Request Forgery (SSRF)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-11T14:13:35.906Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Windows",
                "Linux"
              ],
              "product": "Commvault Cloud",
              "vendor": "Commvault",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "11.46.10",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.46.9",
                  "status": "affected",
                  "version": "11.46.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.44.11",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.44.10",
                  "status": "affected",
                  "version": "11.44.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.40.63",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.40.62",
                  "status": "affected",
                  "version": "11.40.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11.36.114",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.36.113",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Peter V., Principal Researcher, CFC Security LTD."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs.  Software customers upgrade to resolved maintenance release.  Update Command Center."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-918: Server-Side Request Forgery (SSRF)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-11T11:01:38.340Z",
            "orgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
            "shortName": "Commvault"
          },
          "references": [
            {
              "url": "https://documentation.commvault.com/securityadvisories/CV_2026_07_5.html"
            }
          ],
          "title": "Server-Side Request Forgery (SSRF)"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
        "assignerShortName": "Commvault",
        "cveId": "CVE-2026-13739",
        "datePublished": "2026-08-11T11:01:38.340Z",
        "dateReserved": "2026-06-29T14:54:17.751Z",
        "dateUpdated": "2026-08-11T14:13:35.906Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-12776 (GCVE-0-2025-12776)

    Vulnerability from cvelistv5 – Published: 2026-01-07 22:03 – Updated: 2026-01-08 18:17
    VLAI
    Title
    Stored Cross-Site Scripting
    Summary
    The Report Builder component of the application stores user input directly in a web page and displays it to other users, which raised concerns about a possible Cross-Site Scripting (XSS) attack. Proper management of this functionality helps ensure a secure and seamless user experience.  Although the user input is not validated in the report creation, these scripts are not executed when the report is run by end users. The script is executed when the report is modified through the report builder by a user with edit permissions. The Report Builder is part of the WebConsole.  The WebConsole package is currently end of life, and is no longer maintained. We strongly recommend against installing or using it in any production environment. However, if you choose to install it, for example, to access functionality like the Report Builder, it must be deployed within a fully isolated network that has no access to sensitive data or internet connectivity. This is a critical security precaution, as the retired package may contain unpatched vulnerabilities and is no longer supported with updates or fixes.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-01-08 15:09 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
    Impacted products
    Vendor Product Version
    Commvault WebConsole Affected: 11.32.0 , ≤ 11.32.* (semver)
    Affected: 11.36.0 , ≤ 11.36.* (semver)
    Unaffected: 11.40.1 , ≤ 11.40.* (semver)
    Unaffected: 11.42.1 , ≤ 11.42.* (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-12776",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-08T15:09:42.351651Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-08T18:17:45.215Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WebConsole",
              "vendor": "Commvault",
              "versions": [
                {
                  "lessThanOrEqual": "11.32.*",
                  "status": "affected",
                  "version": "11.32.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "11.36.*",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "11.40.*",
                  "status": "unaffected",
                  "version": "11.40.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "11.42.*",
                  "status": "unaffected",
                  "version": "11.42.1",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "NCIA researchers"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003eThe Report Builder component of the application stores user input directly in a web page and displays it to other users, which raised concerns about a possible Cross-Site Scripting (XSS) attack. Proper management of this functionality helps ensure a secure and seamless user experience. \u0026nbsp;Although the user input is not validated in the report creation, these scripts are not executed when the report is run by end users. The script is executed when the report is modified through the report builder by a user with edit permissions. \u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eThe Report Builder is part of the WebConsole. \u0026nbsp;The WebConsole package is currently end of life, and is no longer maintained. We strongly recommend against installing or using it in any production environment. However, if you choose to install it, for example, to access functionality like the Report Builder, it must be deployed within a fully isolated network that has no access to sensitive data or internet connectivity. This is a critical security precaution, as the retired package may contain unpatched vulnerabilities and is no longer supported with updates or fixes.\u0026nbsp;\u0026nbsp;\u003c/div\u003e\u003cbr\u003e\u003cbr\u003e"
                }
              ],
              "value": "The Report Builder component of the application stores user input directly in a web page and displays it to other users, which raised concerns about a possible Cross-Site Scripting (XSS) attack. Proper management of this functionality helps ensure a secure and seamless user experience. \u00a0Although the user input is not validated in the report creation, these scripts are not executed when the report is run by end users. The script is executed when the report is modified through the report builder by a user with edit permissions. \n\n\n\n\nThe Report Builder is part of the WebConsole. \u00a0The WebConsole package is currently end of life, and is no longer maintained. We strongly recommend against installing or using it in any production environment. However, if you choose to install it, for example, to access functionality like the Report Builder, it must be deployed within a fully isolated network that has no access to sensitive data or internet connectivity. This is a critical security precaution, as the retired package may contain unpatched vulnerabilities and is no longer supported with updates or fixes."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 1.8,
                "baseSeverity": "LOW",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "ACTIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or \u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-01-07T22:08:14.195Z",
            "orgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
            "shortName": "Commvault"
          },
          "references": [
            {
              "url": "https://documentation.commvault.com/securityadvisories/CV_2025_06_3.html"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Stored Cross-Site Scripting",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
        "assignerShortName": "Commvault",
        "cveId": "CVE-2025-12776",
        "datePublished": "2026-01-07T22:03:05.033Z",
        "dateReserved": "2025-11-05T20:18:49.381Z",
        "dateUpdated": "2026-01-08T18:17:45.215Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-57791 (GCVE-0-2025-57791)

    Vulnerability from cvelistv5 – Published: 2025-08-20 03:22 – Updated: 2025-09-10 15:41
    VLAI
    Title
    Argument Injection Vulnerability in CommServe
    Summary
    A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input validation. Successful exploitation results in a valid user session for a low privilege role.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-08-20 13:04 UTC
    CWE
    • CWE-88 - Improper Neutralization of Argument Delimiters in a Command
    Impacted products
    Vendor Product Version
    Commvault CommCell Affected: 11.32.0 , ≤ 11.32.101 (semver)
    Affected: 11.36.0 , ≤ 11.36.59 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-57791",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-08-20T13:04:55.463863Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-08-20T13:12:32.533Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CommCell",
              "vendor": "Commvault",
              "versions": [
                {
                  "lessThanOrEqual": "11.32.101",
                  "status": "affected",
                  "version": "11.32.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "11.36.59",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Sonny and Piotr Bazydlo (@chudyPB) of watchTowr"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input validation. Successful exploitation results in a valid user session for a low privilege role."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-88",
                  "description": "CWE-88: Improper Neutralization of Argument Delimiters in a Command",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-09-10T15:41:57.068Z",
            "orgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
            "shortName": "Commvault"
          },
          "references": [
            {
              "url": "https://documentation.commvault.com/securityadvisories/CV_2025_08_1.html"
            }
          ],
          "title": "Argument Injection Vulnerability in CommServe"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2025-57791",
        "datePublished": "2025-08-20T03:22:12.633Z",
        "dateReserved": "2025-08-19T18:25:57.338Z",
        "dateUpdated": "2025-09-10T15:41:57.068Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-57790 (GCVE-0-2025-57790)

    Vulnerability from cvelistv5 – Published: 2025-08-20 03:22 – Updated: 2025-09-11 14:03
    VLAI
    Title
    Path Traversal Vulnerability
    Summary
    A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulnerability may lead to remote code execution.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-09-11 14:03 UTC
    CWE
    • CWE-36 - Absolute Path Traversal
    Impacted products
    Vendor Product Version
    Commvault CommCell Affected: 11.32.0 , ≤ 11.32.101 (semver)
    Affected: 11.36.0 , ≤ 11.36.59 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-57790",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-09-11T14:03:09.226926Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-09-11T14:03:15.394Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CommCell",
              "vendor": "Commvault",
              "versions": [
                {
                  "lessThanOrEqual": "11.32.101",
                  "status": "affected",
                  "version": "11.32.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "11.36.59",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Sonny and Piotr Bazydlo (@chudyPB) of watchTowr"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulnerability may lead to remote code execution."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-36",
                  "description": "CWE-36: Absolute Path Traversal",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-09-10T15:51:14.395Z",
            "orgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
            "shortName": "Commvault"
          },
          "references": [
            {
              "url": "https://documentation.commvault.com/securityadvisories/CV_2025_08_2.html"
            }
          ],
          "title": "Path Traversal Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2025-57790",
        "datePublished": "2025-08-20T03:22:10.697Z",
        "dateReserved": "2025-08-19T18:25:57.338Z",
        "dateUpdated": "2025-09-11T14:03:15.394Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-57789 (GCVE-0-2025-57789)

    Vulnerability from cvelistv5 – Published: 2025-08-20 03:22 – Updated: 2026-02-26 17:48
    VLAI
    Title
    Vulnerability in Initial Administrator Login Process
    Summary
    During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-08-21 03:55 UTC
    CWE
    • CWE-257 - Storing Passwords in a Recoverable Format
    Impacted products
    Vendor Product Version
    Commvault CommCell Affected: 11.32.0 , ≤ 11.32.101 (semver)
    Affected: 11.36.0 , ≤ 11.36.59 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-57789",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-08-21T03:55:09.971466Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T17:48:25.835Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CommCell",
              "vendor": "Commvault",
              "versions": [
                {
                  "lessThanOrEqual": "11.32.101",
                  "status": "affected",
                  "version": "11.32.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "11.36.59",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Sonny and Piotr Bazydlo (@chudyPB) of watchTowr"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-257",
                  "description": "CWE-257: Storing Passwords in a Recoverable Format",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-09-10T15:54:49.968Z",
            "orgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
            "shortName": "Commvault"
          },
          "references": [
            {
              "url": "https://documentation.commvault.com/securityadvisories/CV_2025_08_4.html"
            }
          ],
          "title": "Vulnerability in Initial Administrator Login Process"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2025-57789",
        "datePublished": "2025-08-20T03:22:08.764Z",
        "dateReserved": "2025-08-19T18:25:57.338Z",
        "dateUpdated": "2026-02-26T17:48:25.835Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-57788 (GCVE-0-2025-57788)

    Vulnerability from cvelistv5 – Published: 2025-08-20 00:00 – Updated: 2025-09-11 14:02
    VLAI
    Title
    Unauthorized API Access Risk
    Summary
    A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-09-11 14:02 UTC
    CWE
    • CWE-259 - Use of Hard-coded Password
    Impacted products
    Vendor Product Version
    Commvault CommCell Affected: 11.32.0 , ≤ 11.32.101 (semver)
    Affected: 11.36.0 , ≤ 11.36.59 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-57788",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-09-11T14:02:08.558353Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-09-11T14:02:30.986Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://labs.watchtowr.com/guess-who-would-be-stupid-enough-to-rob-the-same-vault-twice-pre-auth-rce-chains-in-commvault/#wt-2025-0047hardcoded-credentials"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CommCell",
              "vendor": "Commvault",
              "versions": [
                {
                  "lessThanOrEqual": "11.32.101",
                  "status": "affected",
                  "version": "11.32.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "11.36.59",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Sonny and Piotr Bazydlo (@chudyPB) of watchTowr"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-259",
                  "description": "CWE-259: Use of Hard-coded Password",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-09-10T16:00:55.240Z",
            "orgId": "050066fd-a2f9-4f32-ab5d-4c53f48bc333",
            "shortName": "Commvault"
          },
          "references": [
            {
              "url": "https://documentation.commvault.com/securityadvisories/CV_2025_08_3.html"
            }
          ],
          "title": "Unauthorized API Access Risk"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2025-57788",
        "datePublished": "2025-08-20T00:00:00.000Z",
        "dateReserved": "2025-08-19T00:00:00.000Z",
        "dateUpdated": "2025-09-11T14:02:30.986Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-13976 (GCVE-0-2024-13976)

    Vulnerability from cvelistv5 – Published: 2025-07-25 15:50 – Updated: 2025-11-22 12:20
    VLAI
    Title
    Commvault 11.20.0 - 11.36.0 Windows Maintenance Installer DLL Injection
    Summary
    A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit uncontrolled search path or DLL loading behavior to execute arbitrary code with elevated privileges. The vulnerability has been resolved in versions 11.20.202, 11.28.124, 11.32.65, 11.34.37, and 11.36.15.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-07-25 17:48 UTC
    CWE
    • CWE-427 - Uncontrolled Search Path Element
    References
    Impacted products
    Vendor Product Version
    Commvault Commvault for Windows Affected: 11.20.0 , < 11.20.202 (semver)
    Affected: 11.28.0 , < 11.28.124 (semver)
    Affected: 11.32.0 , < 11.32.65 (semver)
    Affected: 11.34.0 , < 11.34.37 (semver)
    Affected: 11.36.0 , < 11.36.15 (semver)
        cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
        cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
        cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
        cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
        cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-13976",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-07-25T17:48:27.935953Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-07-25T17:49:35.606Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Windows Maintenance Release Installer"
              ],
              "platforms": [
                "Windows"
              ],
              "product": "Commvault for Windows",
              "vendor": "Commvault",
              "versions": [
                {
                  "lessThan": "11.20.202",
                  "status": "affected",
                  "version": "11.20.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.28.124",
                  "status": "affected",
                  "version": "11.28.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.32.65",
                  "status": "affected",
                  "version": "11.32.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.34.37",
                  "status": "affected",
                  "version": "11.34.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.36.15",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "11.20.202",
                      "versionStartIncluding": "11.20.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "11.28.124",
                      "versionStartIncluding": "11.28.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "11.32.65",
                      "versionStartIncluding": "11.32.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "11.34.37",
                      "versionStartIncluding": "11.34.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "11.36.15",
                      "versionStartIncluding": "11.36.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Commvault"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit uncontrolled search path or DLL loading behavior to execute arbitrary code with elevated privileges.\u0026nbsp;The vulnerability has been resolved in versions 11.20.202, 11.28.124, 11.32.65, 11.34.37, and 11.36.15.\u003c/p\u003e"
                }
              ],
              "value": "A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit uncontrolled search path or DLL loading behavior to execute arbitrary code with elevated privileges.\u00a0The vulnerability has been resolved in versions 11.20.202, 11.28.124, 11.32.65, 11.34.37, and 11.36.15."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-641",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-641 DLL Side-Loading"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-427",
                  "description": "CWE-427 Uncontrolled Search Path Element",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-11-22T12:20:44.890Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://documentation.commvault.com/securityadvisories/CV_2024_09_2.html"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/commvault-for-windows-maintenance-installer-dll-injection"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Commvault 11.20.0 - 11.36.0 Windows Maintenance Installer DLL Injection",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2024-13976",
        "datePublished": "2025-07-25T15:50:17.950Z",
        "dateReserved": "2025-07-23T20:30:07.057Z",
        "dateUpdated": "2025-11-22T12:20:44.890Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-13975 (GCVE-0-2024-13975)

    Vulnerability from cvelistv5 – Published: 2025-07-25 15:49 – Updated: 2025-11-22 12:22
    VLAI
    Title
    Commvault 11.20.0 - 11.36.0 Windows Access Nodes Compromise via Local File Server Agent Abuse
    Summary
    A local privilege escalation vulnerability exists in Commvault for Windows versions 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. In affected configurations, a local attacker who owns a client system with the file server agent installed can compromise any assigned Windows access nodes. This may allow unauthorized access or lateral movement within the backup infrastructure. The issue has been resolved in versions 11.32.60, 11.34.34, and 11.36.8.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-07-25 17:50 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    References
    Impacted products
    Vendor Product Version
    Commvault Commvault Affected: 11.20.0 , < 11.32.60 (semver)
    Affected: 11.28.0 , < 11.32.60 (semver)
    Affected: 11.32.0 , < 11.32.60 (semver)
    Affected: 11.34.0 , < 11.34.34 (semver)
    Affected: 11.36.0 , < 11.36.8 (semver)
        cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
        cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
        cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
        cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
        cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-13975",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-07-25T17:50:32.007572Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-07-25T17:52:28.580Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "File Server Agent / Access Node Assignment Logic"
              ],
              "platforms": [
                "Windows"
              ],
              "product": "Commvault",
              "vendor": "Commvault",
              "versions": [
                {
                  "lessThan": "11.32.60",
                  "status": "affected",
                  "version": "11.20.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.32.60",
                  "status": "affected",
                  "version": "11.28.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.32.60",
                  "status": "affected",
                  "version": "11.32.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.34.34",
                  "status": "affected",
                  "version": "11.34.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.36.8",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "11.32.60",
                      "versionStartIncluding": "11.20.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "11.32.60",
                      "versionStartIncluding": "11.28.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "11.32.60",
                      "versionStartIncluding": "11.32.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "11.34.34",
                      "versionStartIncluding": "11.34.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "11.36.8",
                      "versionStartIncluding": "11.36.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Commvault"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\u003c/p\u003e\u003cp\u003eA local privilege escalation vulnerability exists in Commvault for Windows versions 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. In affected configurations, a local attacker who owns a client system with the file server agent installed can compromise any assigned Windows access nodes. This may allow unauthorized access or lateral movement within the backup infrastructure. The issue has been resolved in versions 11.32.60, 11.34.34, and 11.36.8.\u003c/p\u003e\n\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "A local privilege escalation vulnerability exists in Commvault for Windows versions 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. In affected configurations, a local attacker who owns a client system with the file server agent installed can compromise any assigned Windows access nodes. This may allow unauthorized access or lateral movement within the backup infrastructure. The issue has been resolved in versions 11.32.60, 11.34.34, and 11.36.8."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269 Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-11-22T12:22:01.173Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://documentation.commvault.com/securityadvisories/CV_2024_09_1.html"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/commvault-for-windows-access-nodes-compromise"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Commvault 11.20.0 - 11.36.0 Windows Access Nodes Compromise via Local File Server Agent Abuse",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2024-13975",
        "datePublished": "2025-07-25T15:49:51.852Z",
        "dateReserved": "2025-07-23T20:21:13.240Z",
        "dateUpdated": "2025-11-22T12:22:01.173Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-34136 (GCVE-0-2025-34136)

    Vulnerability from cvelistv5 – Published: 2025-07-25 15:49 – Updated: 2025-11-19 01:28
    VLAI
    Title
    Commvault CommServe Web Server Unauthenticated SQL Injection
    Summary
    An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server roles are installed. Other Commvault components deployed in the same environment are not affected.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-07-25 18:30 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    References
    Impacted products
    Vendor Product Version
    Commvault Commvault Affected: 11.32.0 , ≤ 11.32.93 (semver)
    Affected: 11.36.0 , ≤ 11.36.51 (semver)
    Affected: 11.38.0 , ≤ 11.38.19 (semver)
        cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
        cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
        cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-34136",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-07-25T18:30:37.202196Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-07-25T18:31:26.584Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "CVWebService"
              ],
              "platforms": [
                "Linux",
                "Windows"
              ],
              "product": "Commvault",
              "vendor": "Commvault",
              "versions": [
                {
                  "lessThanOrEqual": "11.32.93",
                  "status": "affected",
                  "version": "11.32.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "11.36.51",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "11.38.19",
                  "status": "affected",
                  "version": "11.38.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "11.32.93",
                      "versionStartIncluding": "11.32.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "11.36.51",
                      "versionStartIncluding": "11.36.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "11.38.19",
                      "versionStartIncluding": "11.38.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eAn SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server roles are installed. Other Commvault components deployed in the same environment are not affected.\u003c/p\u003e"
                }
              ],
              "value": "An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server roles are installed. Other Commvault components deployed in the same environment are not affected."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-66",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-66 SQL Injection"
                }
              ]
            },
            {
              "capecId": "CAPEC-137",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-137 Parameter Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-11-19T01:28:56.047Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://documentation.commvault.com/securityadvisories/CV_2025_04_2.html"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/commvault-commserve-web-server-unauth-sqli"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Commvault CommServe Web Server Unauthenticated SQL Injection",
          "x_generator": {
            "engine": "vulncheck"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2025-34136",
        "datePublished": "2025-07-25T15:49:23.837Z",
        "dateReserved": "2025-04-15T19:15:22.562Z",
        "dateUpdated": "2025-11-19T01:28:56.047Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-3928 (GCVE-0-2025-3928)

    Vulnerability from cvelistv5 – Published: 2025-04-25 15:56 – Updated: 2026-02-26 18:28
    VLAI
    Title
    Commvault Web Server unspecified vulnerability
    Summary
    Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · cisa-cg (v2.0.3)
    Decision recorded 2025-04-25 17:58 UTC
    Exploitation: active Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-30 03:56 UTC
    Impacted products
    Vendor Product Version
    Commvault Web Server Affected: 11.36.0 , < 11.36.46 (custom)
    Unaffected: 11.36.46
    Affected: 11.32.0 , < 11.32.89 (custom)
    Unaffected: 11.32.89
    Affected: 11.28.0 , < 11.28.141 (custom)
    Unaffected: 11.28.141
    Affected: 11.20.0 , < 11.20.217 (custom)
    Unaffected: 11.20.217
    Create a notification for this product.
    Date Public
    2025-02-24 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-3928",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-30T03:56:24.936967Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2025-04-28",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3928"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T18:28:03.538Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3928"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2025-04-28T00:00:00.000Z",
                "value": "CVE-2025-3928 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-05-05T13:34:41.408Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.bleepingcomputer.com/news/security/commvault-says-recent-breach-didnt-impact-customer-backup-data/"
              }
            ],
            "title": "CVE Program Container",
            "x_generator": {
              "engine": "ADPogram 0.0.1"
            }
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Web Server",
              "vendor": "Commvault",
              "versions": [
                {
                  "lessThan": "11.36.46",
                  "status": "affected",
                  "version": "11.36.0",
                  "versionType": "custom"
                },
                {
                  "status": "unaffected",
                  "version": "11.36.46"
                },
                {
                  "lessThan": "11.32.89",
                  "status": "affected",
                  "version": "11.32.0",
                  "versionType": "custom"
                },
                {
                  "status": "unaffected",
                  "version": "11.32.89"
                },
                {
                  "lessThan": "11.28.141",
                  "status": "affected",
                  "version": "11.28.0",
                  "versionType": "custom"
                },
                {
                  "status": "unaffected",
                  "version": "11.28.141"
                },
                {
                  "lessThan": "11.20.217",
                  "status": "affected",
                  "version": "11.20.0",
                  "versionType": "custom"
                },
                {
                  "status": "unaffected",
                  "version": "11.20.217"
                }
              ]
            }
          ],
          "datePublic": "2025-02-24T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: \"Webservers can be compromised through bad actors creating and executing webshells.\" Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            },
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              }
            },
            {
              "other": {
                "content": {
                  "id": "CVE-2025-3928",
                  "options": [
                    {
                      "Exploitation": "none"
                    },
                    {
                      "Automatable": "no"
                    },
                    {
                      "Technical Impact": "total"
                    }
                  ],
                  "role": "CISA Coordinator",
                  "timestamp": "2025-04-25T17:58:52.842478Z",
                  "version": "2.0.3"
                },
                "type": "ssvc"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-noinfo Not enough information",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-05-27T20:03:27.556Z",
            "orgId": "9119a7d8-5eab-497f-8521-727c672e3725",
            "shortName": "cisa-cg"
          },
          "references": [
            {
              "name": "url",
              "url": "https://documentation.commvault.com/securityadvisories/CV_2025_03_1.html"
            },
            {
              "name": "url",
              "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-3928"
            },
            {
              "name": "url",
              "url": "https://www.commvault.com/blogs/security-advisory-march-7-2025"
            },
            {
              "name": "url",
              "url": "https://www.commvault.com/blogs/notice-security-advisory-update"
            },
            {
              "name": "url",
              "url": "https://www.cisa.gov/news-events/alerts/2025/05/22/advisory-update-cyber-threat-activity-targeting-commvaults-saas-cloud-application-metallic"
            },
            {
              "name": "url",
              "url": "https://www.commvault.com/blogs/customer-security-update"
            }
          ],
          "title": "Commvault Web Server unspecified vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9119a7d8-5eab-497f-8521-727c672e3725",
        "assignerShortName": "cisa-cg",
        "cveId": "CVE-2025-3928",
        "datePublished": "2025-04-25T15:56:28.112Z",
        "dateReserved": "2025-04-24T19:55:32.578Z",
        "dateUpdated": "2026-02-26T18:28:03.538Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-34028 (GCVE-0-2025-34028)

    Vulnerability from cvelistv5 – Published: 2025-04-22 16:32 – Updated: 2025-11-29 02:06
    VLAI
    Title
    Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
    Summary
    The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP. This issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436 and also fixed in 11.38.25 with SP38-CU25-434 and SP38-CU25-438.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-05-02 17:42 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    • CWE-306 - Missing Authentication for Critical Function
    Impacted products
    Vendor Product Version
    Commvault Command Center Innovation Release Affected: 11.38.0 , ≤ 11.38.25 (semver)
        cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-34028",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-05-02T17:42:06.282554Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2025-05-02",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-34028"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-21T22:55:18.317Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-34028"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2025-05-02T00:00:00.000Z",
                "value": "CVE-2025-34028 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Command Center Innovation Release",
              "vendor": "Commvault",
              "versions": [
                {
                  "lessThanOrEqual": "11.38.25",
                  "status": "affected",
                  "version": "11.38.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "11.38.25",
                      "versionStartIncluding": "11.38.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Sonny of watchTowr"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003eThe Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP.\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eThis issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436 and also fixed in 11.38.25 with SP38-CU25-434 and SP38-CU25-438.\u003c/div\u003e"
                }
              ],
              "value": "The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP.\n\n\n\n\n\nThis issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436 and also fixed in 11.38.25 with SP38-CU25-434 and SP38-CU25-438."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-242",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-242 Code Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306 Missing Authentication for Critical Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-11-29T02:06:36.031Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://documentation.commvault.com/securityadvisories/CV_2025_04_1.html"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://labs.watchtowr.com/fire-in-the-hole-were-breaching-the-vault-commvault-remote-code-execution-cve-2025-34028/"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://github.com/watchtowrlabs/watchTowr-vs-Commvault-PreAuth-RCE-CVE-2025-34028"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/commvault-command-center-innovation-release-unauthenticated-install-package-path-traversal"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Commvault Command Center Innovation Release \u003c= 11.38.25 Unathenticated Install Package Path Traversal",
          "x_generator": {
            "engine": "vulncheck"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2025-34028",
        "datePublished": "2025-04-22T16:32:23.446Z",
        "dateReserved": "2025-04-15T19:15:22.545Z",
        "dateUpdated": "2025-11-29T02:06:36.031Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2021-34997 (GCVE-0-2021-34997)

    Vulnerability from cvelistv5 – Published: 2022-01-13 21:44 – Updated: 2024-08-04 00:26
    VLAI
    Summary
    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the AppStudioUploadHandler class. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-13894.
    CWE
    • CWE-434 - Unrestricted Upload of File with Dangerous Type
    Assigner
    References
    Impacted products
    Vendor Product Version
    Commvault CommCell Affected: 11.22.22
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T00:26:55.760Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1332/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CommCell",
              "vendor": "Commvault",
              "versions": [
                {
                  "status": "affected",
                  "version": "11.22.22"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "kpc"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the AppStudioUploadHandler class. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-13894."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-434",
                  "description": "CWE-434: Unrestricted Upload of File with Dangerous Type",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-01-13T21:44:51.000Z",
            "orgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
            "shortName": "zdi"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1332/"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "zdi-disclosures@trendmicro.com",
              "ID": "CVE-2021-34997",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CommCell",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "11.22.22"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Commvault"
                  }
                ]
              }
            },
            "credit": "kpc",
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the AppStudioUploadHandler class. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-13894."
                }
              ]
            },
            "impact": {
              "cvss": {
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-434: Unrestricted Upload of File with Dangerous Type"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://www.zerodayinitiative.com/advisories/ZDI-21-1332/",
                  "refsource": "MISC",
                  "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1332/"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
        "assignerShortName": "zdi",
        "cveId": "CVE-2021-34997",
        "datePublished": "2022-01-13T21:44:51.000Z",
        "dateReserved": "2021-06-17T00:00:00.000Z",
        "dateUpdated": "2024-08-04T00:26:55.760Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-34996 (GCVE-0-2021-34996)

    Vulnerability from cvelistv5 – Published: 2022-01-13 21:44 – Updated: 2024-08-04 00:26
    VLAI
    Summary
    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Demo_ExecuteProcessOnGroup workflow. By creating a workflow, an attacker can specify an arbitrary command to be executed. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-13889.
    CWE
    • CWE-749 - Exposed Dangerous Method or Function
    Assigner
    References
    Impacted products
    Vendor Product Version
    Commvault CommCell Affected: 11.22.22
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T00:26:55.917Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1331/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CommCell",
              "vendor": "Commvault",
              "versions": [
                {
                  "status": "affected",
                  "version": "11.22.22"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Brandon Perry, Justin Kennedy and Steven Seeley of Source Incite"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Demo_ExecuteProcessOnGroup workflow. By creating a workflow, an attacker can specify an arbitrary command to be executed. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-13889."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-749",
                  "description": "CWE-749: Exposed Dangerous Method or Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-01-13T21:44:49.000Z",
            "orgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
            "shortName": "zdi"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1331/"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "zdi-disclosures@trendmicro.com",
              "ID": "CVE-2021-34996",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CommCell",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "11.22.22"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Commvault"
                  }
                ]
              }
            },
            "credit": "Brandon Perry, Justin Kennedy and Steven Seeley of Source Incite",
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Demo_ExecuteProcessOnGroup workflow. By creating a workflow, an attacker can specify an arbitrary command to be executed. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-13889."
                }
              ]
            },
            "impact": {
              "cvss": {
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-749: Exposed Dangerous Method or Function"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://www.zerodayinitiative.com/advisories/ZDI-21-1331/",
                  "refsource": "MISC",
                  "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1331/"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
        "assignerShortName": "zdi",
        "cveId": "CVE-2021-34996",
        "datePublished": "2022-01-13T21:44:49.000Z",
        "dateReserved": "2021-06-17T00:00:00.000Z",
        "dateUpdated": "2024-08-04T00:26:55.917Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-34995 (GCVE-0-2021-34995)

    Vulnerability from cvelistv5 – Published: 2022-01-13 21:44 – Updated: 2024-08-04 00:26
    VLAI
    Summary
    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the DownloadCenterUploadHandler class. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-13756.
    CWE
    • CWE-434 - Unrestricted Upload of File with Dangerous Type
    Assigner
    References
    Impacted products
    Vendor Product Version
    Commvault CommCell Affected: 11.22.22
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T00:26:55.743Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1330/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CommCell",
              "vendor": "Commvault",
              "versions": [
                {
                  "status": "affected",
                  "version": "11.22.22"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Brandon Perry, Justin Kennedy and Steven Seeley of Source Incite"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the DownloadCenterUploadHandler class. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-13756."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-434",
                  "description": "CWE-434: Unrestricted Upload of File with Dangerous Type",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-01-13T21:44:48.000Z",
            "orgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
            "shortName": "zdi"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1330/"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "zdi-disclosures@trendmicro.com",
              "ID": "CVE-2021-34995",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CommCell",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "11.22.22"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Commvault"
                  }
                ]
              }
            },
            "credit": "Brandon Perry, Justin Kennedy and Steven Seeley of Source Incite",
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the DownloadCenterUploadHandler class. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-13756."
                }
              ]
            },
            "impact": {
              "cvss": {
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-434: Unrestricted Upload of File with Dangerous Type"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://www.zerodayinitiative.com/advisories/ZDI-21-1330/",
                  "refsource": "MISC",
                  "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1330/"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
        "assignerShortName": "zdi",
        "cveId": "CVE-2021-34995",
        "datePublished": "2022-01-13T21:44:48.000Z",
        "dateReserved": "2021-06-17T00:00:00.000Z",
        "dateUpdated": "2024-08-04T00:26:55.743Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-34994 (GCVE-0-2021-34994)

    Vulnerability from cvelistv5 – Published: 2022-01-13 21:44 – Updated: 2024-08-04 00:26
    VLAI
    Summary
    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the DataProvider class. The issue results from the lack of proper validation of a user-supplied string before executing it as JavaScript code. An attacker can leverage this vulnerability to escape the JavaScript sandbox and execute Java code in the context of NETWORK SERVICE. Was ZDI-CAN-13755.
    CWE
    • CWE-20 - Improper Input Validation
    Assigner
    References
    Impacted products
    Vendor Product Version
    Commvault CommCell Affected: 11.22.22
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T00:26:55.855Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1329/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CommCell",
              "vendor": "Commvault",
              "versions": [
                {
                  "status": "affected",
                  "version": "11.22.22"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Brandon Perry, Justin Kennedy and Steven Seeley of Source Incite"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the DataProvider class. The issue results from the lack of proper validation of a user-supplied string before executing it as JavaScript code. An attacker can leverage this vulnerability to escape the JavaScript sandbox and execute Java code in the context of NETWORK SERVICE. Was ZDI-CAN-13755."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20: Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-01-13T21:44:47.000Z",
            "orgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
            "shortName": "zdi"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1329/"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "zdi-disclosures@trendmicro.com",
              "ID": "CVE-2021-34994",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CommCell",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "11.22.22"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Commvault"
                  }
                ]
              }
            },
            "credit": "Brandon Perry, Justin Kennedy and Steven Seeley of Source Incite",
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the DataProvider class. The issue results from the lack of proper validation of a user-supplied string before executing it as JavaScript code. An attacker can leverage this vulnerability to escape the JavaScript sandbox and execute Java code in the context of NETWORK SERVICE. Was ZDI-CAN-13755."
                }
              ]
            },
            "impact": {
              "cvss": {
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-20: Improper Input Validation"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://www.zerodayinitiative.com/advisories/ZDI-21-1329/",
                  "refsource": "MISC",
                  "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1329/"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
        "assignerShortName": "zdi",
        "cveId": "CVE-2021-34994",
        "datePublished": "2022-01-13T21:44:47.000Z",
        "dateReserved": "2021-06-17T00:00:00.000Z",
        "dateUpdated": "2024-08-04T00:26:55.855Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-34993 (GCVE-0-2021-34993)

    Vulnerability from cvelistv5 – Published: 2022-01-13 21:44 – Updated: 2024-08-04 00:26
    VLAI
    Summary
    This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CVSearchService service. The issue results from the lack of proper validation prior to authentication. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-13706.
    CWE
    • CWE-287 - Improper Authentication
    Assigner
    References
    Impacted products
    Vendor Product Version
    Commvault CommCell Affected: 11.22.22
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T00:26:55.745Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1328/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CommCell",
              "vendor": "Commvault",
              "versions": [
                {
                  "status": "affected",
                  "version": "11.22.22"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Brandon Perry, Justin Kennedy and Steven Seeley of Source Incite"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CVSearchService service. The issue results from the lack of proper validation prior to authentication. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-13706."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "CWE-287: Improper Authentication",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-01-13T21:44:46.000Z",
            "orgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
            "shortName": "zdi"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1328/"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "zdi-disclosures@trendmicro.com",
              "ID": "CVE-2021-34993",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CommCell",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "11.22.22"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Commvault"
                  }
                ]
              }
            },
            "credit": "Brandon Perry, Justin Kennedy and Steven Seeley of Source Incite",
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CVSearchService service. The issue results from the lack of proper validation prior to authentication. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-13706."
                }
              ]
            },
            "impact": {
              "cvss": {
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-287: Improper Authentication"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://www.zerodayinitiative.com/advisories/ZDI-21-1328/",
                  "refsource": "MISC",
                  "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1328/"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
        "assignerShortName": "zdi",
        "cveId": "CVE-2021-34993",
        "datePublished": "2022-01-13T21:44:46.000Z",
        "dateReserved": "2021-06-17T00:00:00.000Z",
        "dateUpdated": "2024-08-04T00:26:55.745Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2017-3195 (GCVE-0-2017-3195)

    Vulnerability from cvelistv5 – Published: 2017-12-15 14:00 – Updated: 2024-08-05 14:16
    VLAI
    Summary
    Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges.
    Severity
    No CVSS data available.
    CWE
    • CWE-121 - Stack-based Buffer Overflow
    References
    URL Tags
    http://kb.commvault.com/article/SEC0013 x_refsource_CONFIRM
    http://redr2e.com/commvault-edge-cve-2017-3195/ x_refsource_MISC
    https://www.exploit-db.com/exploits/41823/ exploitx_refsource_EXPLOIT-DB
    https://www.kb.cert.org/vuls/id/214283 third-party-advisoryx_refsource_CERT-VN
    http://www.securityfocus.com/bid/96941 vdb-entryx_refsource_BID
    Impacted products
    Vendor Product Version
    Commvault Service Pack 6 Affected: Version 11 prior to SP7
    Affected: version 11 SP6 prior to hotfix 590
    Create a notification for this product.
    Date Public
    2017-03-16 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T14:16:28.351Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://kb.commvault.com/article/SEC0013"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://redr2e.com/commvault-edge-cve-2017-3195/"
              },
              {
                "name": "41823",
                "tags": [
                  "exploit",
                  "x_refsource_EXPLOIT-DB",
                  "x_transferred"
                ],
                "url": "https://www.exploit-db.com/exploits/41823/"
              },
              {
                "name": "VU#214283",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_CERT-VN",
                  "x_transferred"
                ],
                "url": "https://www.kb.cert.org/vuls/id/214283"
              },
              {
                "name": "96941",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/96941"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Service Pack 6",
              "vendor": "Commvault",
              "versions": [
                {
                  "status": "affected",
                  "version": "Version 11 prior to SP7"
                },
                {
                  "status": "affected",
                  "version": "version 11 SP6 prior to hotfix 590"
                }
              ]
            }
          ],
          "datePublic": "2017-03-16T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121: Stack-based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-12-15T13:57:01.000Z",
            "orgId": "37e5125f-f79b-445b-8fad-9564f167944b",
            "shortName": "certcc"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://kb.commvault.com/article/SEC0013"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://redr2e.com/commvault-edge-cve-2017-3195/"
            },
            {
              "name": "41823",
              "tags": [
                "exploit",
                "x_refsource_EXPLOIT-DB"
              ],
              "url": "https://www.exploit-db.com/exploits/41823/"
            },
            {
              "name": "VU#214283",
              "tags": [
                "third-party-advisory",
                "x_refsource_CERT-VN"
              ],
              "url": "https://www.kb.cert.org/vuls/id/214283"
            },
            {
              "name": "96941",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/96941"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cert@cert.org",
              "ID": "CVE-2017-3195",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Service Pack 6",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Version 11 prior to SP7"
                              },
                              {
                                "version_value": "version 11 SP6 prior to hotfix 590"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Commvault"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-121: Stack-based Buffer Overflow"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "http://kb.commvault.com/article/SEC0013",
                  "refsource": "CONFIRM",
                  "url": "http://kb.commvault.com/article/SEC0013"
                },
                {
                  "name": "http://redr2e.com/commvault-edge-cve-2017-3195/",
                  "refsource": "MISC",
                  "url": "http://redr2e.com/commvault-edge-cve-2017-3195/"
                },
                {
                  "name": "41823",
                  "refsource": "EXPLOIT-DB",
                  "url": "https://www.exploit-db.com/exploits/41823/"
                },
                {
                  "name": "VU#214283",
                  "refsource": "CERT-VN",
                  "url": "https://www.kb.cert.org/vuls/id/214283"
                },
                {
                  "name": "96941",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/96941"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "37e5125f-f79b-445b-8fad-9564f167944b",
        "assignerShortName": "certcc",
        "cveId": "CVE-2017-3195",
        "datePublished": "2017-12-15T14:00:00.000Z",
        "dateReserved": "2016-12-05T00:00:00.000Z",
        "dateUpdated": "2024-08-05T14:16:28.351Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }