logo

Commvault: Vulnerability Patch Works as Intended

ID: a391799a-ef95-56d1-82e7-37207feb1a03

STIX ID: report--a391799a-ef95-56d1-82e7-37207feb1a03

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-05-09

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Commvault disclosed a maximum-severity pre-auth SSRF (CVE-2025-34028, CVSS 10.0) in Command Center that can lead to complete compromise of affected environments; fixes were released in 11.38.20 and 11.38.25 with additional updates (SP38-CU20-433 / SP38-CU20-436 and SP38-CU25-434 / SP38-CU25-438). A researcher reported that a proof-of-concept still worked against updated systems, but Commvault said the researcher tested unregistered/trial instances that had not received the manual additional updates; Commvault reports no signs of active exploitation and has broadened patch availability to trial users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.