ZeroHour

CVE-2025-57791

large

Unauthenticated Argument Injection in Commvault Grants Low-Privilege Sessions

CVSS 4.0
6.9 medium
EPSS
22%p98
Published
()
Modified
AI analysis

CVE-2025-57791 is an argument injection flaw (CWE-88) in Commvault's data-protection suite in which insufficient input validation allows remote attackers to inject or manipulate command-line arguments passed to internal components. It is triggered over the network without prior authentication, user interaction, or privileges, per the CVSS 4.0 vector (AV:N/PR:N/UI:N). A successful attacker obtains a valid user session at a low-privilege role, which related advisories indicate can be chained with other pre-auth Commvault flaws to enable remote code execution. Any organization running affected Commvault software is exposed, particularly deployments whose Commvault web interfaces are reachable from the internet. No public proof-of-concept is known and the flaw is not yet in CISA's KEV, but EPSS places it in the 98th percentile (22.4% probability of exploitation within 30 days), and Commvault has already released fixes.

What to do: Apply the patches Commvault has released for this issue, using the version guidance in the vendor's security advisory since exact fixed build numbers are not included in the available data. Because the bug is pre-authentication, restrict internet-facing access to Commvault web/console interfaces to trusted networks or behind VPN, and check access logs for unexpected low-privilege session creation or command-argument anomalies. Treat it as urgent given the 98th-percentile EPSS score and the reported risk of pre-auth exploit chains reaching remote code execution.

Affected
Commvault
Estimated exposure
largetens of thousands of enterprise deployments worldwide, with only a few thousand Commvault web consoles exposed to the public internet — Commvault is a widely deployed enterprise backup platform with roughly 24,000+ customer organizations (implying tens of thousands of installed server deployments), while public internet scans typically show only on the order of a few…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input validation. Successful exploitation results in a valid user session for a low privilege role.

Vendors
commvault
Products
commvault
Weakness
CWE-88
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news