Command Injection Vulnerability in Commvault Software
CVE-2025-57791
6.9MEDIUM
What is CVE-2025-57791?
A vulnerability has been identified in Commvault software that allows remote actors to perform command injection due to inadequate input validation. This flaw enables attackers to manipulate command-line arguments, leading to unauthorized access through the establishment of a valid user session with low privilege. Protective measures and updates are strongly recommended to secure affected versions.
Affected Version(s)
CommCell 11.32.0 <= 11.32.101
CommCell 11.36.0 <= 11.36.59