Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Commvault — Vulnerabilities & Security Advisories 30

Browse all 30 CVE security advisories affecting Commvault. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Commvault provides enterprise data management and backup solutions, serving as critical infrastructure for data protection and recovery. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation, often stemming from authentication bypasses or insecure default configurations. While no major public security incidents have been widely reported, the 16 documented CVEs highlight potential risks in web interfaces and API endpoints. The platform's security posture emphasizes encryption and access controls, though organizations should regularly patch and audit deployments to mitigate exposure to known exploits targeting its backup and data management capabilities.

CVE ID Title CVSS Severity Published
CVE-2026-77106 Cvlaunchd Code Execution — Commvault Cloud 7.7 High 2026-09-08
CVE-2026-77105 CommServe Privilege Escalation — Commvault Cloud 8.7 High 2026-09-08
CVE-2026-77104 CommServe Path Traversal — Commvault Cloud 8.3 High 2026-09-08
CVE-2026-77103 CommServe Information Disclosure — Commvault Cloud 8.7 High 2026-09-08
CVE-2026-77092 Content Extractor Privilege Escalation — Commvault Cloud 7.3 High 2026-09-08
CVE-2026-77102 CommServe Denial of Service — Commvault Cloud 8.7 High 2026-09-08
CVE-2026-77097 Private Metrics Server Denial of Service — Commvault Cloud 8.8 High 2026-09-08
CVE-2026-77101 CommServe Stack-based Buffer Overflow — Commvault Cloud 8.7 High 2026-09-08
CVE-2026-77098 Private Metrics Server SQL Injection — Commvault Cloud 8.8 High 2026-09-08
CVE-2026-77091 DataCube Security Feature Bypass — Commvault Cloud 8.5 High 2026-09-08
CVE-2026-77089 Command Center API Authentication Bypass — Commvault Cloud 9.3 Critical 2026-09-08
CVE-2026-13738 Improper Authorization Validation — Commvault Cloud 9.2 Critical 2026-08-11
CVE-2026-13737 Command Restriction Bypass — Commvault Cloud 9.2 Critical 2026-08-11
CVE-2026-13739 Server-Side Request Forgery (SSRF) — Commvault Cloud 8.8 High 2026-08-11
CVE-2025-12776 Stored Cross-Site Scripting — WebConsole CWE-79 5.4 - 2026-01-07
CVE-2025-57791 Argument Injection Vulnerability in CommServe — CommCell CWE-88 8.8 - 2025-08-20
CVE-2025-57790 Path Traversal Vulnerability — CommCell CWE-36 9.8 - 2025-08-20
CVE-2025-57789 Vulnerability in Initial Administrator Login Process — CommCell CWE-257 8.1 - 2025-08-20
CVE-2025-57788 Unauthorized API Access Risk — CommCell CWE-259 9.4 - 2025-08-20
CVE-2024-13976 Commvault 11.20.0 - 11.36.0 Windows Maintenance Installer DLL Injection — Commvault for Windows CWE-427 7.3 - 2025-07-25
CVE-2024-13975 Commvault 11.20.0 - 11.36.0 Windows Access Nodes Compromise via Local File Server Agent Abuse — Commvault CWE-269 6.7 - 2025-07-25
CVE-2025-34136 Commvault CommServe Web Server Unauthenticated SQL Injection — Commvault CWE-89 9.8 - 2025-07-25
CVE-2025-3928 Commvault Web Server unspecified vulnerability — Web Server 8.8 High 2025-04-25
CVE-2025-34028 Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal — Command Center Innovation Release CWE-22 9.8 - 2025-04-22
CVE-2021-34997 Commvault CommCell 代码问题漏洞 — CommCell CWE-434 8.8 - 2022-01-13
CVE-2021-34996 Commvault CommCell 安全漏洞 — CommCell CWE-749 8.8 - 2022-01-13
CVE-2021-34995 Commvault CommCell 代码问题漏洞 — CommCell CWE-434 8.8 - 2022-01-13
CVE-2021-34994 Commvault CommCell 代码注入漏洞 — CommCell CWE-20 8.8 - 2022-01-13
CVE-2021-34993 Commvault CommCell 授权问题漏洞 — CommCell CWE-287 9.8 - 2022-01-13
CVE-2017-3195 Commvault Edge Communication Service 缓冲区错误漏洞 — Service Pack 6 CWE-121 9.8 - 2017-12-15

This page lists every published CVE security advisory associated with Commvault. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.