Commvault Security Advisories & CVEs
22 advisories tracked · Commvault Cloud Security Advisories · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Commvault CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Check if your Commvault device is affected
Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Commvault's recent advisories.
Official source
Commvault Cloud Security Advisories
Polled by parsing the official Commvault security-advisories index (documentation.commvault.com), which lists every CV_YYYY_MM_N advisory with its CVEs and dates. Advisory pages are fetched for new items to extract severity, impacted products and the Feature Release / Maintenance Release fix table.
Latest Commvault advisories
Critical [CVE-2026-13738] Improper Authorization Validation
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customer upgrade to resolved maintenance release.CVSS score: 9.2 Commvault Software To view version support lifecyle, see Commvault software releases, release types, and release tracks. Versions not listed are out of support or unaffected. Product Platforms Affected Versions Resolved Version Status Commvault Linux, Windows 11.46.0 - 11.46.9 11.46.10 and above Resolved Commvault Linux, Windows 11.44.0 - 11.44.10 11.44.11 and above Resolved Commvault Linux, Windows 11.40.0 - 11.40.62 11.40.63 and above Resolved Commvault Linux, Windows 11.36.0 - 11.36.113 11.36.114 and above Resolved Affected product named by the advisory: Commvault Cloud.
Critical [CVE-2026-13737] Command Restriction Bypass
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release.CVSS score: 9.2 Commvault Software To view version support lifecyle, see Commvault software releases, release types, and release tracks. Versions not listed are out of support or unaffected. Product Platforms Affected Versions Resolved Version Status Commvault Linux, Windows 11.46.0 - 11.46.9 11.46.10 and above Resolved Commvault Linux, Windows 11.44.0 - 11.44.10 11.44.11 and above Resolved Commvault Linux, Windows 11.40.0 - 11.40.62 11.40.63 and above Resolved Commvault Linux, Windows 11.36.0 - 11.36.113 11.36.114 and above Resolved Affected product named by the advisory: Commvault Cloud.
High [CVE-2026-13739] Server-Side Request Forgery (SSRF)
A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs.Software customers upgrade to resolved maintenance release.CVSS score: 8.8 Commvault Software To view version support lifecyle, see Commvault software releases, release types, and release tracks. Versions not listed are out of support or unaffected. Product Platforms Affected Versions Resolved Version Status Commvault Linux, Windows 11.46.0 - 11.46.9 11.46.10 and above Resolved Commvault Linux, Windows 11.44.0 - 11.44.10 11.44.11 and above Resolved Commvault Linux, Windows 11.40.0 - 11.40.62 11.40.63 and above Resolved Commvault Linux, Windows 11.36.0 - 11.36.113 11.36.114 and above Resolved Affected product named by the advisory: Commvault Cloud.
Low OTP Invalidation Missing Upon Regeneration
OTP Invalidation Missing Upon Regeneration
Low [CVE-2025-14847] MongoBleed: MongoDB Memory Disclosure Vulnerability (CVE-2025-14847)
MongoBleed: MongoDB Memory Disclosure Vulnerability (CVE-2025-14847)
Low Stored Cross-Site Scripting Vulnerability
Stored Cross-Site Scripting Vulnerability
High [CVE-2025-57790] Path Traversal Vulnerability
A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulnerability may lead to remote code execution.CVSS Score: 8.7 High Commvault Software The following versions are impacted. Versions that are not listed are either out of support or unaffected. To view version support lifecyle, see Platform Release Schedule and Lifecycles. Product Platforms Affected Versions Resolved Version Status Commvault Linux, Windows 11.32.0 - 11.32.101 11.32.102 Resolved Commvault Linux, Windows 11.36.0 - 11.36.59 11.36.60 Resolved
Medium [CVE-2025-57788] Unauthorized API Access Risk
A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.CVSS Score: 6.9 Medium Commvault Software The following versions are impacted. Versions that are not listed are either out of support or unaffected. To view version support lifecyle, see Platform Release Schedule and Lifecycles. Product Platforms Affected Versions Resolved Version Status Commvault Linux, Windows 11.32.0 - 11.32.101 11.32.102 Resolved Commvault Linux, Windows 11.36.0 - 11.36.59 11.36.60 Resolved
Medium [CVE-2025-57791] Argument Injection Vulnerability in CommServe
Argument Injection Vulnerability in CommServe
Medium [CVE-2025-57789] Vulnerability in Initial Administrator Login Process
Vulnerability in Initial Administrator Login Process
Critical [CVE-2025-34028] Vulnerability in Commvault Command Center Installation
Vulnerability in Commvault Command Center Installation
High [CVE-2025-3928] Critical Webserver Vulnerability
CVE.Org link: CVE-2025-3928 Save as PDF A vulnerability has been identified and remediated in all supported versions of the Commvault software. Webservers can be compromised through bad actors creating and executing webshells. Exploiting this vulnerability requires a bad actor to have authenticated user credentials within the Commvault Software environment. Unauthenticated access is not exploitable. For software customers, this means your environment must be: (i) accessible via the internet, (ii) compromised through an unrelated avenue, and (iii) accessed leveraging legitimate user credentials.
Medium SQL Injection Vulnerability
Save as PDF A security vulnerability has been identified in the CommServe and Web Server installation that allows a remote SQL Injection attack without authentication. Other installations in the same system are not compromised by this vulnerability.CVSS Score: 5.5
Medium DLL Injection Vulnerability in the Software Installation Path
DLL Injection Vulnerability in the Software Installation Path
Critical SQL Injection and Command Injection Advisory
SQL Injection and Command Injection Advisory
Medium Security vulnerability in Windows access nodes that are used for file server data protection
Security vulnerability in Windows access nodes that are used for file server data protection
Critical [CVE-2023-46604] Remote Code Execution Vulnerability in Apache ActiveMQ
Remote Code Execution Vulnerability in Apache ActiveMQ
Critical [CVE-2023-4863] Libwebp Vulnerability
CVE.Org link: CVE-2023-4863 Save as PDF
Critical Volt Typhoon Advisory
Save as PDF Impacted Products With the recent announcement of the Volt Typhoon cyber campaign, our team has conducted a thorough security assessment of Commvault and Commvault Cloud services and have found no impact to the security, privacy, or integrity of your data backups. Resolution We also recommend you to check your Commvault and Commvault Cloud environment to ensure security controls such as the following are active:MFA is properly configured and up to dateDual authorization workflows are in place for backup and restore operationsCompliance locks are enabled for services, apps, and backup destinationsAdditionally, for customers looking for an extra layer of protection, we encourage you to evaluate ThreatWise, capable of surfacing zero-day and unknown threats in production environments. On this page
Critical [CVE-2021-4104 +4] Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products