Showing 3 vulnerabilities on this page for Commvault

Signals CISA KEV Ransomware Nuclei
Commvault vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Unauthorized API Access Risk

A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.

CWE-259Aug 20, 20251 related artifact
CVSS6.9v4.0EPSS2.8%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Commvault 11.20.0 - 11.36.0 Windows Access Nodes Compromise via Local File Server Agent Abuse

A local privilege escalation vulnerability exists in Commvault for Windows versions 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. In affected configurations, a local attacker who owns a client system with the file server agent installed can compromise any assigned Windows access nodes. This may allow unauthorized access or lateral movement within the backup infrastructure. The issue has been resolved in versions 11.32.60, 11.34.34, and 11.36.8.

CWE-269Jul 25, 2025
CVSS8.5v4.0EPSS0.119%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Commvault CommServe Web Server Unauthenticated SQL Injection

An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server roles are installed. Other Commvault components deployed in the same environment are not affected.

CWE-89Jul 25, 2025
CVSS6.9v4.0EPSS0.464%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX