CVE-2025-57788 is a medium-severity vulnerability affecting Commvault products, allowing unauthenticated attackers to execute API calls without credentials due to a flaw in a login mechanism. This vulnerability has a CVSS score of 6.5 and an extremely high EPSS score, indicating a significant likelihood of exploitation. While Role-Based Access Control (RBAC) can limit exposure, it does not fully mitigate the risk of information disclosure or integrity compromise. Exploit code, including a Metasploit module for remote code execution and Nuclei templates for password disclosure, is publicly available, and the CVE has garnered substantial community discussion, though it is not yet listed on the KEV catalog or actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.36.60CPE matchmatch criteria | cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:* | ||
>= 11.32.0, <= 11.32.101CPE match | cpe:2.3:a:commvault:commcell:*:*:*:*:*:*:*:* | ||
>= 11.36.0, <= 11.36.59CPE match | cpe:2.3:a:commvault:commcell:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Unauthorized API Access Risk
Aug 19, 2025Unauthorized API Access Risk
Aug 19, 2025Unauthorized API Access Risk
Aug 19, 2025Unauthorized API Access Risk
Aug 19, 2025Unauthorized API Access Risk
Aug 19, 2025Unauthorized API Access Risk
Aug 19, 2025Unauthorized API Access Risk
Aug 19, 2025Unauthorized API Access Risk
Aug 19, 2025