Commvault Vulnerabilities and Affected Products
Vulnerabilities associated with Commvault.
Products
Clear product- CommCell9 vulnerabilities
- Commvault3 vulnerabilities
- Commvault Cloud3 vulnerabilities
- Command Center1 vulnerability
- Command Center Innovation Release1 vulnerability
- Commvault for Windows1 vulnerability
- Service Pack 61 vulnerability
- Web Server1 vulnerability
- WebConsole1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-57788MEDIUM | Unauthorized API Access RiskA vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk. | CVSS6.9v4.0 | EPSS2.8% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-13975HIGH | Commvault 11.20.0 - 11.36.0 Windows Access Nodes Compromise via Local File Server Agent AbuseA local privilege escalation vulnerability exists in Commvault for Windows versions 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. In affected configurations, a local attacker who owns a client system with the file server agent installed can compromise any assigned Windows access nodes. This may allow unauthorized access or lateral movement within the backup infrastructure. The issue has been resolved in versions 11.32.60, 11.34.34, and 11.36.8. CWE-269Jul 25, 2025 | CVSS8.5v4.0 | EPSS0.119% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-34136MEDIUM | Commvault CommServe Web Server Unauthenticated SQL InjectionAn SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server roles are installed. Other Commvault components deployed in the same environment are not affected. CWE-89Jul 25, 2025 | CVSS6.9v4.0 | EPSS0.464% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |