Skip to content
VulniPulse

Commvault Security Advisories & CVEs

7 advisories tracked · Commvault Cloud Security Advisories · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Commvault CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Commvault device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Commvault's recent advisories.

Official source

Commvault Cloud Security Advisories

Polled by parsing the official Commvault security-advisories index (documentation.commvault.com), which lists every CV_YYYY_MM_N advisory with its CVEs and dates. Advisory pages are fetched for new items to extract severity, impacted products and the Feature Release / Maintenance Release fix table.

Latest Commvault advisories

Medium6.9Commvault

Medium [CVE-2025-57788] Unauthorized API Access Risk

A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.CVSS Score: 6.9 Medium Commvault Software The following versions are impacted. Versions that are not listed are either out of support or unaffected. To view version support lifecyle, see Platform Release Schedule and Lifecycles. Product Platforms Affected Versions Resolved Version Status Commvault Linux, Windows 11.32.0 - 11.32.101 11.32.102 Resolved Commvault Linux, Windows 11.36.0 - 11.36.59 11.36.60 Resolved

CVE-2025-57788
Unclassified
Sep 3, 2025
Medium6.9Commvault

Medium [CVE-2025-57791] Argument Injection Vulnerability in CommServe

Argument Injection Vulnerability in CommServe

CVE-2025-57791
Backup & Recovery
Sep 3, 2025
Medium5.3Commvault

Medium [CVE-2025-57789] Vulnerability in Initial Administrator Login Process

Vulnerability in Initial Administrator Login Process

CVE-2025-57789
Unclassified
Sep 3, 2025
Medium5.5Commvault

Medium SQL Injection Vulnerability

Save as PDF A security vulnerability has been identified in the CommServe and Web Server installation that allows a remote SQL Injection attack without authentication. Other installations in the same system are not compromised by this vulnerability.CVSS Score: 5.5

Backup & RecoveryWeb Server / Command Center
Apr 16, 2025
MediumCommvault

Medium DLL Injection Vulnerability in the Software Installation Path

DLL Injection Vulnerability in the Software Installation Path

Unclassified
Oct 2, 2024
MediumCommvault

Medium Security vulnerability in Windows access nodes that are used for file server data protection

Security vulnerability in Windows access nodes that are used for file server data protection

Unclassified
Sep 16, 2024
MediumCommvault

Medium Authentication Bypass Vulnerabilities on CVWebService Endpoint

Authentication Bypass Vulnerabilities on CVWebService Endpoint

Web Server / Command Center
Aug 8, 2021

← All vendors