VYPR

Command Center

by Commvault

CVEs (3)

  • CVE-2025-34028CriKEVApr 22, 2025
    risk 0.85cvss 10.0epss 0.98

    The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious…

  • CVE-2026-13738CriAug 11, 2026
    risk 0.60cvss epss

    CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents,…

  • CVE-2026-13739HigAug 11, 2026
    risk 0.57cvss epss

    A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center.