Executive brief
Commvault Content Extractor, a component used to process and extract data from various file formats in backup and recovery operations, contains a vulnerability that allows an attacker to escalate privileges. An exploit of this issue could allow an unauthorized user to gain elevated access to the system, potentially enabling theft of sensitive backup data or disruption of critical data protection operations.
Technical details
The vulnerability is a deserialization of untrusted data (CWE-502) issue in Commvault Content Extractor that affects privilege management. The root cause lies in unsafe deserialization of untrusted input, which can be exploited to achieve privilege escalation. The attack vector is not explicitly specified in the advisory but deserialization flaws typically require network access and may not require authentication depending on the exposure of the vulnerable component. An attacker who exploits this vulnerability can escalate privileges within the affected system. Patches are available: versions 11.46.20+, 11.44.20+, 11.40.72+, and 11.36.123+ resolve the issue.
Affected products
- Commvault Content Extractor 11.46.0-11.46.19, 11.44.0-11.44.19, 11.40.0-11.40.71, 11.36.0-11.36.122
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Fixed in versions 11.46.20+, 11.44.20+, 11.40.72+, 11.36.123+