Vulnerability record · CVE-2021-34995 · published 13 January 2022
CVE-2021-34995: Commvault CommCell unrestricted file upload leads to remote code execution
Commvault · Commcell
Commvault CommCell 11.22.22 fails to validate user-supplied data in the DownloadCenterUploadHandler class, allowing an attacker to upload arbitrary files. Because the existing authentication mechanism can be bypassed, a remote attacker can reach the flaw despite the nominal authentication requirement. Successful exploitation results in code execution in the context of the NETWORK SERVICE account.
Description
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the DownloadCenterUploadHandler class. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-13756.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability, low privileges, no user interaction, and a very high EPSS score make this a serious pre-auth-bypass RCE risk despite no KEV listing.
What it is
Commvault CommCell 11.22.22 fails to validate user-supplied data in the DownloadCenterUploadHandler class, allowing an attacker to upload arbitrary files. Because the existing authentication mechanism can be bypassed, a remote attacker can reach the flaw despite the nominal authentication requirement. Successful exploitation results in code execution in the context of the NETWORK SERVICE account.
Impact
An attacker gains arbitrary code execution on the affected CommCell installation under the NETWORK SERVICE account, which can lead to full compromise of the backup server and any data or credentials it manages.
Attack surface
The flaw is network-reachable (AV:N) and requires no user interaction (UI:N), but the CVSS vector lists low privileges (PR:L); the description states the authentication mechanism can be bypassed, so effective access may not require valid credentials.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware association is recorded, but EPSS is high at 0.68864 (99.3rd percentile), indicating elevated likelihood of exploitation activity.
What to do
- Apply the vendor patch for Commvault CommCell 11.22.22 or upgrade to a fixed release as directed by Commvault.
- Restrict network access to the CommCell DownloadCenter interface to trusted management networks only.
- Enforce strong authentication and monitor for authentication bypass attempts against the CommCell web interface.
- Audit and lock down file upload paths and permissions so uploaded files cannot execute in the NETWORK SERVICE context.
- Review CommCell logs for unexpected file uploads and disable unused upload functionality where possible.
Detection
- Monitor CommCell web server logs for POST requests to DownloadCenterUploadHandler endpoints with unusual file names or extensions.
- Alert on new files written to CommCell upload or web-accessible directories, especially executable or script file types.
- Track processes spawned by the NETWORK SERVICE account that originate from CommCell web directories.
- Correlate authentication bypass indicators, such as anomalous session or token use, with subsequent upload activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-21-1330/ | Third Party AdvisoryVDB Entry |
| https://www.zerodayinitiative.com/advisories/ZDI-21-1330/ | Third Party AdvisoryVDB Entry |
Track CVE-2021-34995 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-34995), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.