Vulnerability record · CVE-2025-34028 · published 22 April 2025
CVE-2025-34028: Commvault Command Center unauthenticated ZIP upload path traversal RCE
Commvault · Commvault
Commvault Command Center Innovation Release accepts unauthenticated uploads of ZIP install packages that are expanded without safe path handling, allowing path traversal. An attacker can write a malicious JSP outside the intended directory and achieve remote code execution on the server. The flaw affects versions 11.38.0 through 11.38.20 and is fixed in 11.38.20 and 11.38.25 maintenance updates.
Description
The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP. This issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436 and also fixed in 11.38.25 with SP38-CU25-434 and SP38-CU25-438.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with a public exploit, CISA KEV listing and near-certain EPSS score makes this an urgent patch-first issue.
What it is
Commvault Command Center Innovation Release accepts unauthenticated uploads of ZIP install packages that are expanded without safe path handling, allowing path traversal. An attacker can write a malicious JSP outside the intended directory and achieve remote code execution on the server. The flaw affects versions 11.38.0 through 11.38.20 and is fixed in 11.38.20 and 11.38.25 maintenance updates.
Impact
An unauthenticated attacker gains remote code execution on the Command Center server, enabling full compromise of the host and any data or credentials it can reach. Because the product is a backup and data management platform, this can expose or destroy protected backup data.
Attack surface
Reachable over the network via the Command Center web interface with no authentication and no user interaction, per the CVSS 4.0 vector (AV:N/PR:N/UI:N). The attacker only needs to submit a crafted ZIP install package to the upload function.
Exploitation
CVE-2025-34028 is listed in CISA KEV with a 2025-05-23 remediation due date, and EPSS gives a 30-day probability of 0.977 (99.9th percentile). A public proof-of-concept exploit is referenced, so active exploitation should be assumed.
What to do
- Upgrade to 11.38.20 with SP38-CU20-433 and SP38-CU20-436, or to 11.38.25 with SP38-CU25-434 and SP38-CU25-438, as directed by the vendor advisory.
- If patching cannot be completed immediately, restrict network access to the Command Center interface to trusted management networks only.
- Follow CISA BOD 22-01 guidance for cloud services and apply the vendor mitigations or discontinue use where mitigations are unavailable.
- Review and remove any unexpected JSP files or install packages written to the Command Center web directories.
- Rotate credentials and secrets stored on or reachable from the Command Center host if compromise is suspected.
Detection
- Monitor Command Center logs and web server access logs for unauthenticated POST requests to install package or upload endpoints.
- Alert on new or modified JSP files appearing in Command Center web-accessible directories outside expected deployment paths.
- Hunt for ZIP archives containing path traversal sequences (../) or JSP payloads submitted to the Command Center service.
- Correlate unexpected child processes spawned by the Command Center web service, which may indicate post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-34028 to the Known Exploited Vulnerabilities catalog on 2 May 2025 as "Commvault Command Center Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 May 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-34028 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-34028), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.