Executive brief
Commvault Cvlaunchd is a system service used across Commvault backup and recovery software deployments. A missing authorization check allows an attacker to execute arbitrary commands without proper authentication, potentially compromising all connected systems in a Commvault environment including backup servers, clients, and management infrastructure.
Technical details
Cvlaunchd contains a missing authorization issue affecting command execution authorization, classified as a code execution vulnerability. The vulnerable component fails to properly validate authorization before executing commands, allowing attackers to bypass authentication controls. This vulnerability affects multiple Commvault components across Linux and Windows platforms (Commserve, Webserver, Command Center, Media Agents, Clients, and HyperScale X). Exploitation requires network access to affected Commvault installations but does not require prior authentication. Patches are available in resolved maintenance releases: 11.46.20+, 11.44.20+, 11.40.72+, and 11.36.123+ for affected versions.
Affected products
- Commvault Commvault 11.36.0 - 11.36.122, 11.40.0 - 11.40.71, 11.44.0 - 11.44.19, 11.46.0 - 11.46.19
Timeline
- 2026-09-08: disclosed