Executive brief
Commvault CommServe is the core backup and data management platform used to protect enterprise data. A stack-based buffer overflow vulnerability allows an attacker to crash the service or potentially execute code, disrupting backup operations and data protection across an organization.
Technical details
The vulnerability is a stack-based buffer overflow in CommServe, Commvault's central backup and recovery service. The root cause and attack vector are not detailed in the advisory, but the impact is limited to service availability (crash/denial of service). Commvault has issued patches for all supported versions: 11.46.20+, 11.44.20+, 11.40.72+, and 11.36.123+. Customers must upgrade to the resolved maintenance releases.
Affected products
- Commvault CommServe 11.36.0–11.36.122, 11.40.0–11.40.71, 11.44.0–11.44.19, 11.46.0–11.46.19
Timeline
- 2026-09-08: disclosed