Executive brief
Commvault Command Center is a management and monitoring platform used by enterprises to oversee backup and recovery operations. A flaw in a legacy endpoint allows unauthenticated attackers to make arbitrary network requests on behalf of the server, potentially accessing internal services, exfiltrating data from the organization's infrastructure, or facilitating lateral movement within the corporate network.
Technical details
The vulnerability is an unauthenticated server-side request forgery (SSRF) in a legacy endpoint of Commvault Command Center related to improper handling of arbitrary target URLs. The affected endpoint requires no authentication, allowing any network-accessible attacker to craft requests that cause the server to perform HTTP/HTTPS requests to arbitrary internal or external targets. An attacker can exploit this to access internal services, retrieve metadata from cloud environments, or probe the organization's internal network topology. The vulnerability affects Commvault versions 11.46.0–11.46.9, 11.44.0–11.44.10, 11.40.0–11.40.62, and 11.36.0–11.36.113 on Linux and Windows platforms. Patches are available as of 2026-08-11 via maintenance releases: 11.46.10, 11.44.11, 11.40.63, and 11.36.114 or higher.
Affected products
- Commvault Command Center 11.36.0–11.36.113, 11.40.0–11.40.62, 11.44.0–11.44.10, 11.46.0–11.46.9
Timeline
- 2026-08-11: disclosed
- 2026-08-11: patched: Resolved versions: 11.36.114+, 11.40.63+, 11.44.11+, 11.46.10+