Critical Commvault Security Flaws Allow Hackers to Take Complete Control Without Authentication


# Commvault Patches Critical Security Flaws That Enable Remote Code Execution

Commvault has issued security updates to fix four serious vulnerabilities that could allow cybercriminals to remotely execute malicious code on vulnerable systems. These security gaps affect Commvault versions prior to 11.36.60 and pose significant risks to organizations using the data management platform.

## The Four Critical Vulnerabilities

Security researchers from watchTowr Labs discovered these flaws in April 2025:

**CVE-2025-57788 (CVSS: 6.9)** – Attackers can bypass authentication and execute API calls without valid user credentials through a compromised login mechanism.

**CVE-2025-57789 (CVSS: 5.3)** – During the initial setup window between installation and first admin login, attackers can exploit default credentials to gain administrative access.

**CVE-2025-57790 (CVSS: 8.7)** – A path traversal flaw allows unauthorized file system access, potentially leading to complete system compromise through remote code execution.

**CVE-2025-57791 (CVSS: 6.9)** – Insufficient input validation enables attackers to manipulate command-line arguments, creating unauthorized user sessions with elevated privileges.

## Dangerous Exploit Combinations

Cybersecurity experts warn that these vulnerabilities can be chained together in two particularly dangerous ways:

1. **First attack chain**: Combines CVE-2025-57791 and CVE-2025-57790
2. **Second attack chain**: Links CVE-2025-57788, CVE-2025-57789, and CVE-2025-57790

The second attack method only succeeds if administrators haven’t changed the default password after installation—a common oversight in many organizations.

## Immediate Action Required

Commvault has resolved all vulnerabilities in versions 11.32.102 and 11.36.60. Organizations should immediately update their systems to these patched versions. Notably, Commvault’s SaaS solution remains unaffected by these security issues.

## Growing Security Concerns

This disclosure follows a pattern of serious Commvault vulnerabilities. In late 2024, researchers identified CVE-2025-34028, a maximum-severity flaw (CVSS: 10.0) in Commvault Command Center. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) later added this vulnerability to its Known Exploited Vulnerabilities catalog after detecting active attacks in the wild.

Organizations using Commvault should prioritize these security updates and review their patch management processes to prevent future exploitation attempts.

Share This Article