CVE-2025-57790 Details
Description
A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulnerability may lead to remote code execution.
A path traversal vulnerability has been identified in Commvault versions 11.32.0 prior to 11.32.102 and 11.36.0 prior to 11.36.60. This vulnerability allows remote attackers to access the file system unauthorizedly, potentially leading to remote code execution.
Users are advised to install the resolved maintenance release for their affected version on the Web Server. Commvault SaaS is not affected by this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://documentation.commvault.com/securityadvisories/CV_2025_08_2.html | Commvault | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-36 | Absolute Path Traversal | Commvault |
Affected Products
| Product | Versions |
|---|---|
| commvault commvault | < 11.36.60 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Commvault |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 10, 2025 | CVE Modified | Commvault |
| Aug 21, 2025 | Initial Analysis | [email protected] |
| Aug 20, 2025 | New CVE Received | [email protected] |