← Vulnerability feed

Vulnerability record · CVE-2025-34028 · published 22 April 2025

CVE-2025-34028: Commvault Command Center unauthenticated ZIP upload path traversal RCE

Commvault · Commvault

Commvault Command Center Innovation Release accepts unauthenticated uploads of ZIP install packages that are expanded without safe path handling, allowing path traversal. An attacker can write a malicious JSP outside the intended directory and achieve remote code execution on the server. The flaw affects versions 11.38.0 through 11.38.20 and is fixed in 11.38.20 and 11.38.25 maintenance updates.

9.3 CVSS 4.0 Critical CISA KEV since 2 May 2025 EPSS 98% · top 0.1% CWE-22 · Path traversalCWE-306 · Missing authentication for critical function
9.3CVSS 4.0 base score
98%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP. This issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436 and also fixed in 11.38.25 with SP38-CU25-434 and SP38-CU25-438.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with a public exploit, CISA KEV listing and near-certain EPSS score makes this an urgent patch-first issue.

What it is

Commvault Command Center Innovation Release accepts unauthenticated uploads of ZIP install packages that are expanded without safe path handling, allowing path traversal. An attacker can write a malicious JSP outside the intended directory and achieve remote code execution on the server. The flaw affects versions 11.38.0 through 11.38.20 and is fixed in 11.38.20 and 11.38.25 maintenance updates.

Impact

An unauthenticated attacker gains remote code execution on the Command Center server, enabling full compromise of the host and any data or credentials it can reach. Because the product is a backup and data management platform, this can expose or destroy protected backup data.

Attack surface

Reachable over the network via the Command Center web interface with no authentication and no user interaction, per the CVSS 4.0 vector (AV:N/PR:N/UI:N). The attacker only needs to submit a crafted ZIP install package to the upload function.

Exploitation

CVE-2025-34028 is listed in CISA KEV with a 2025-05-23 remediation due date, and EPSS gives a 30-day probability of 0.977 (99.9th percentile). A public proof-of-concept exploit is referenced, so active exploitation should be assumed.

What to do

  • Upgrade to 11.38.20 with SP38-CU20-433 and SP38-CU20-436, or to 11.38.25 with SP38-CU25-434 and SP38-CU25-438, as directed by the vendor advisory.
  • If patching cannot be completed immediately, restrict network access to the Command Center interface to trusted management networks only.
  • Follow CISA BOD 22-01 guidance for cloud services and apply the vendor mitigations or discontinue use where mitigations are unavailable.
  • Review and remove any unexpected JSP files or install packages written to the Command Center web directories.
  • Rotate credentials and secrets stored on or reachable from the Command Center host if compromise is suspected.

Detection

  • Monitor Command Center logs and web server access logs for unauthenticated POST requests to install package or upload endpoints.
  • Alert on new or modified JSP files appearing in Command Center web-accessible directories outside expected deployment paths.
  • Hunt for ZIP archives containing path traversal sequences (../) or JSP payloads submitted to the Command Center service.
  • Correlate unexpected child processes spawned by the Command Center web service, which may indicate post-exploitation activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-34028 to the Known Exploited Vulnerabilities catalog on 2 May 2025 as "Commvault Command Center Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 May 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-34028 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2025-3928Commvault Web Server webshell upload by authenticated attackerCommvault Web Server contains an unspecified vulnerability that a remote, authenticated attacker can use to create and execute webshells on the serve…KEVEPSS 2.3%analysed9.8CVE-2017-18044Commvault CVDataPipe.dll unauthenticated command injectionThe message parsing function in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6 fails to validate an incoming string before passing it t…EPSS 70%analysed9.3CVE-2026-77089Commvault authentication bypass by spoofing vulnerabilityCommand Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance releas…EPSS 0.61%9.2CVE-2026-13737Commvault incorrect authorization vulnerabilityCommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance r…EPSS 0.52%9.2CVE-2026-13738Commvault incorrect authorization vulnerabilityCommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to reso…EPSS 0.63%8.8CVE-2026-77097Commvault missing authentication for critical function vulnerabilityPrivate Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software custome…EPSS 0.47%8.8CVE-2026-77098Commvault sql injection vulnerabilityPrivate Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release…EPSS 0.47%8.8CVE-2026-13739Commvault server-side request forgery (ssrf) vulnerabilityA legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrar…EPSS 0.39%

Source: NIST National Vulnerability Database (record CVE-2025-34028), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.