CVE-2025-57791
largeUnauthenticated Argument Injection in Commvault Grants Low-Privilege Sessions
CVE-2025-57791 is an argument injection flaw (CWE-88) in Commvault's data-protection suite in which insufficient input validation allows remote attackers to inject or manipulate command-line arguments passed to internal components. It is triggered over the network without prior authentication, user interaction, or privileges, per the CVSS 4.0 vector (AV:N/PR:N/UI:N). A successful attacker obtains a valid user session at a low-privilege role, which related advisories indicate can be chained with other pre-auth Commvault flaws to enable remote code execution. Any organization running affected Commvault software is exposed, particularly deployments whose Commvault web interfaces are reachable from the internet. No public proof-of-concept is known and the flaw is not yet in CISA's KEV, but EPSS places it in the 98th percentile (22.4% probability of exploitation within 30 days), and Commvault has already released fixes.
What to do: Apply the patches Commvault has released for this issue, using the version guidance in the vendor's security advisory since exact fixed build numbers are not included in the available data. Because the bug is pre-authentication, restrict internet-facing access to Commvault web/console interfaces to trusted networks or behind VPN, and check access logs for unexpected low-privilege session creation or command-argument anomalies. Treat it as urgent given the 98th-percentile EPSS score and the reported risk of pre-auth exploit chains reaching remote code execution.
| Commvault | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input validation. Successful exploitation results in a valid user session for a low privilege role.
- Vendors
- commvault
- Products
- commvault
- Weakness
- CWE-88
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X