CVE-2025-57790

8.8

Commvault · CommCell

Commvault CommCell contains an absolute path traversal vulnerability that may allow authenticated remote attackers to perform unauthorized file access and achieve remote code execution.

Executive summary

A critical path traversal vulnerability in Commvault CommCell allows authenticated attackers to perform unauthorized file system operations and potentially execute arbitrary code.

Vulnerability

This vulnerability is caused by an absolute path traversal flaw (CWE-36) that permits an authenticated user to bypass file system restrictions. By manipulating input parameters, an attacker can access sensitive files or potentially achieve remote code execution on the underlying system.

Business impact

The potential for remote code execution and unauthorized file system access poses a severe risk to data confidentiality, integrity, and availability. With a CVSS score of 8.8, this vulnerability represents a high-severity threat that could lead to full system compromise, data exfiltration, or the installation of persistent malicious backdoors within the backup infrastructure.

Remediation

Immediate Action: Administrators must review the official Commvault security advisory at the link provided in the references section and apply the latest security patches or configuration changes as soon as they are made available.

Proactive Monitoring: Security teams should monitor system access logs for unusual file access patterns or attempts to navigate outside of defined application directories.

Compensating Controls: Implement strict network segmentation for the CommCell environment and ensure that service accounts operate with the principle of least privilege to limit the impact of a potential compromise.

Exploitation status

Public Exploit Available: Yes, a Metasploit module exists.

Analyst recommendation

Given the severity of this vulnerability and the availability of a weaponized exploit, immediate action is required. Organizations should identify all instances of the affected Commvault CommCell versions within their environment and prioritize the application of vendor-supplied patches to prevent potential remote code execution.

More Commvault CVEs

Sources

Originally found and disclosed by Sonny and Piotr Bazydlo (@chudyPB) of watchTowr, per the CVE Program record.