CVE-2026-77089
- EPSS 0.33%
- Veröffentlicht 08.09.2026 12:12:53
- Zuletzt bearbeitet 11.09.2026 14:25:43
Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.
CVE-2026-13738
- EPSS 0.53%
- Veröffentlicht 11.08.2026 11:01:39
- Zuletzt bearbeitet 11.09.2026 14:25:13
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Comma...
CVE-2026-13739
- EPSS 0.31%
- Veröffentlicht 11.08.2026 11:01:38
- Zuletzt bearbeitet 09.09.2026 15:55:22
A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center.
CVE-2026-13737
- EPSS 0.43%
- Veröffentlicht 11.08.2026 11:01:38
- Zuletzt bearbeitet 09.09.2026 15:54:24
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Ag...
CVE-2025-12776
- EPSS 0.15%
- Veröffentlicht 07.01.2026 22:15:43
- Zuletzt bearbeitet 02.02.2026 19:32:01
The Report Builder component of the application stores user input directly in a web page and displays it to other users, which raised concerns about a possible Cross-Site Scripting (XSS) attack. Proper management of this functionality helps ensure a ...
CVE-2025-57791
- EPSS 21.43%
- Veröffentlicht 20.08.2025 03:22:12
- Zuletzt bearbeitet 10.09.2025 16:15:40
A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input validation. Successful exploitation results in a valid user session for a...
CVE-2025-57790
- EPSS 16.81%
- Veröffentlicht 20.08.2025 03:22:10
- Zuletzt bearbeitet 10.09.2025 16:15:40
A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulnerability may lead to remote code execution.
CVE-2025-57789
- EPSS 1.15%
- Veröffentlicht 20.08.2025 03:22:08
- Zuletzt bearbeitet 10.09.2025 16:15:40
During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured.
CVE-2025-57788
- EPSS 2.8%
- Veröffentlicht 20.08.2025 00:00:00
- Zuletzt bearbeitet 10.09.2025 16:15:40
A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.
CVE-2025-34136
- EPSS 0.46%
- Veröffentlicht 25.07.2025 16:15:28
- Zuletzt bearbeitet 15.04.2026 00:35:42
An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where th...