CommServe
by Commvault
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-13738 | Cri | 0.64 | 9.8 | 0.01 | Aug 11, 2026 | CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents,… | ||
| CVE-2026-13737 | Cri | 0.64 | 9.8 | 0.01 | Aug 11, 2026 | CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale… | ||
| CVE-2026-77105 | Hig | 0.57 | 8.8 | 0.00 | Sep 8, 2026 | CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server. | ||
| CVE-2026-77104 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2026 | CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe. | ||
| CVE-2026-77103 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2026 | CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe. | ||
| CVE-2026-77102 | Hig | 0.49 | 7.5 | 0.00 | Sep 8, 2026 | CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe. | ||
| CVE-2026-77101 | Hig | 0.49 | 7.5 | 0.00 | Sep 8, 2026 | CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe. |
- risk 0.64cvss 9.8epss 0.01
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents,…
- risk 0.64cvss 9.8epss 0.01
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale…
- risk 0.57cvss 8.8epss 0.00
CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.
- risk 0.49cvss 7.5epss 0.01
CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
- risk 0.49cvss 7.5epss 0.01
CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
- risk 0.49cvss 7.5epss 0.00
CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
- risk 0.49cvss 7.5epss 0.00
CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.