<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Commvault (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/commvault.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/commvault-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Commvault (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:05 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2024-13976 – A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13976</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13976</guid>
    <pubDate>Fri, 25 Jul 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13976</strong></p>
  <p>A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit uncontrolled search path or DLL loading behavior to execute arbitrary code with elevated privileges. The vulnerability has been resolved in versions 11.20.202, 11.28.124, 11.32.65, 11.34.37, and 11.…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13976">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13975 – A local privilege escalation vulnerability exists in Commvault for Windows versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13975</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13975</guid>
    <pubDate>Fri, 25 Jul 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13975</strong></p>
  <p>A local privilege escalation vulnerability exists in Commvault for Windows versions 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. In affected configurations, a local attacker who owns a client system with the file server agent installed can compromise any assigned Windows access nodes. This may allow unauthorized access or lateral movement within the backup infrastructure. The issue has been r…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13975">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3928 – Commvault Web Server has an unspecified vulnerability that can be exploited by a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3928</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3928</guid>
    <pubDate>Fri, 25 Apr 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3928</strong></p>
  <p>Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilit…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3928">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-34028 – The Commvault Command Center Innovation Release allows an unauthenticated actor ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34028</guid>
    <pubDate>Tue, 22 Apr 2025 17:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-34028</strong></p>
  <p>The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP.      This issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-34997 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34997</guid>
    <pubDate>Thu, 13 Jan 2022 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-34997</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the AppStudioUploadHandler class. The issue results from the lack of proper validation of user-supplied data, which ca…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-34996 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34996</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34996</guid>
    <pubDate>Thu, 13 Jan 2022 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-34996</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Demo_ExecuteProcessOnGroup workflow. By creating a workflow, an attacker can specify an arbitrary command to be ex…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-749</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34996">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-34995 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34995</guid>
    <pubDate>Thu, 13 Jan 2022 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-34995</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the DownloadCenterUploadHandler class. The issue results from the lack of proper validation of user-supplied data, whi…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-34994 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34994</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34994</guid>
    <pubDate>Thu, 13 Jan 2022 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-34994</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the DataProvider class. The issue results from the lack of proper validation of a user-supplied string before executin…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34994">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-34993 – This vulnerability allows remote attackers to bypass authentication on affected ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34993</guid>
    <pubDate>Thu, 13 Jan 2022 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-34993</strong></p>
  <p>This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CVSearchService service. The issue results from the lack of proper validation prior to authentication. An attacker can leverage this vulnerability to bypass authentication on…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34993">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-25780 – In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25780</guid>
    <pubDate>Thu, 29 Oct 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-25780</strong></p>
  <p>In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, Directory Traversal can occur such that an attempt to view a log file can instead view a file outside of the log-files folder.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-18044 – A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18044</guid>
    <pubDate>Fri, 19 Jan 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-18044</strong></p>
  <p>A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain message parsing function inside the Commvault service does not properly validate the input of an incoming string before passing it to CreateProcess. As a result, a specially crafted message can inject commands that will be executed on the target operating system. Exploitation of thi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-3195 – Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-3195</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-3195</guid>
    <pubDate>Sat, 16 Dec 2017 02:29:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-3195</strong></p>
  <p>Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-3195">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-7253 – The Web Console in Commvault Edge Server 10 R2 allows remote attackers to execut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7253</guid>
    <pubDate>Wed, 04 Nov 2015 03:59:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-7253</strong></p>
  <p>The Web Console in Commvault Edge Server 10 R2 allows remote attackers to execute arbitrary OS commands via crafted serialized data in a cookie.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7253">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
