← Vulnerability feed

Vulnerability record · CVE-2021-34995 · published 13 January 2022

CVE-2021-34995: Commvault CommCell unrestricted file upload leads to remote code execution

Commvault · Commcell

Commvault CommCell 11.22.22 fails to validate user-supplied data in the DownloadCenterUploadHandler class, allowing an attacker to upload arbitrary files. Because the existing authentication mechanism can be bypassed, a remote attacker can reach the flaw despite the nominal authentication requirement. Successful exploitation results in code execution in the context of the NETWORK SERVICE account.

8.8 CVSS 3.1 High EPSS 69% · top 0.7% CWE-434 · Unrestricted file upload
8.8CVSS 3.1 base score, v2 6.5
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the DownloadCenterUploadHandler class. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-13756.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 8.8 with network reachability, low privileges, no user interaction, and a very high EPSS score make this a serious pre-auth-bypass RCE risk despite no KEV listing.

What it is

Commvault CommCell 11.22.22 fails to validate user-supplied data in the DownloadCenterUploadHandler class, allowing an attacker to upload arbitrary files. Because the existing authentication mechanism can be bypassed, a remote attacker can reach the flaw despite the nominal authentication requirement. Successful exploitation results in code execution in the context of the NETWORK SERVICE account.

Impact

An attacker gains arbitrary code execution on the affected CommCell installation under the NETWORK SERVICE account, which can lead to full compromise of the backup server and any data or credentials it manages.

Attack surface

The flaw is network-reachable (AV:N) and requires no user interaction (UI:N), but the CVSS vector lists low privileges (PR:L); the description states the authentication mechanism can be bypassed, so effective access may not require valid credentials.

Exploitation

Not listed in CISA KEV and no public exploit or ransomware association is recorded, but EPSS is high at 0.68864 (99.3rd percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Apply the vendor patch for Commvault CommCell 11.22.22 or upgrade to a fixed release as directed by Commvault.
  • Restrict network access to the CommCell DownloadCenter interface to trusted management networks only.
  • Enforce strong authentication and monitor for authentication bypass attempts against the CommCell web interface.
  • Audit and lock down file upload paths and permissions so uploaded files cannot execute in the NETWORK SERVICE context.
  • Review CommCell logs for unexpected file uploads and disable unused upload functionality where possible.

Detection

  • Monitor CommCell web server logs for POST requests to DownloadCenterUploadHandler endpoints with unusual file names or extensions.
  • Alert on new files written to CommCell upload or web-accessible directories, especially executable or script file types.
  • Track processes spawned by the NETWORK SERVICE account that originate from CommCell web directories.
  • Correlate authentication bypass indicators, such as anomalous session or token use, with subsequent upload activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-34995 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-34993Commvault commcell improper authentication vulnerabilityThis vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. Authentication is not r…EPSS 5.4%8.8CVE-2021-34996Commvault CommCell workflow command injection allows SYSTEM code executionCommvault CommCell 11.22.22 contains a flaw in the Demo_ExecuteProcessOnGroup workflow that lets an attacker specify an arbitrary command for executi…EPSS 82%analysed8.8CVE-2021-34997Commvault commcell unrestricted file upload vulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authenticatio…EPSS 4.2%8.8CVE-2021-34994Commvault commcell improper input validation vulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authenticatio…EPSS 5.8%7.5CVE-2020-25780Commvault commcell path traversal vulnerabilityIn CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, Directory Traversal can occur …EPSS 9.9%10.0CVE-2026-56291Balbooa Forms Joomla extension unauthenticated arbitrary file upload RCEThe Balbooa Forms extension for Joomla before version 2.4.1 accepts file uploads without authentication and does not restrict file type, allowing exe…KEVEPSS 15%analysed10.0CVE-2026-48939iCagenda Joomla extension unrestricted file upload leads to PHP RCEThe iCagenda extension for Joomla fails to restrict file types in its file attachment feature, allowing arbitrary file uploads that result in PHP cod…KEVEPSS 20%analysed10.0CVE-2026-56290Joomla Page Builder CK unauthenticated file upload leads to RCEThe Joomla Page Builder CK extension before 3.6.0 allows unauthenticated arbitrary file uploads, letting an attacker place executable files on the se…KEVEPSS 31%analysed

Source: NIST National Vulnerability Database (record CVE-2021-34995), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.