logo

Multiple Vulnerabilities in Commvault Backup & Recovery Could Allow for Remote Code Execution

ID: b380892e-066f-513b-a2fb-6cb3a13db55b

STIX ID: report--b380892e-066f-513b-a2fb-6cb3a13db55b

Feed Name: CISecurity.org Advisories

Threat Score
75/100

Date Published: 2025-08-26

Date Updated: 2026-04-27

...
...

Multiple high-severity vulnerabilities in Commvault Backup & Recovery (CVE-2025-57788–57791) allow unauthenticated API access, default-credential privilege escalation during initial setup, path traversal to access the file system, and command-line argument injection; the report describes two RCE chains (one dependent on an unchanged built-in admin password, and one that can deploy a webshell on any unpatched instance).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.