← Vulnerability feed

Vulnerability record · CVE-2025-3928 · published 25 April 2025

CVE-2025-3928: Commvault Web Server webshell upload by authenticated attacker

Commvault · Commvault

Commvault Web Server contains an unspecified vulnerability that a remote, authenticated attacker can use to create and execute webshells on the server. Because it allows code execution on a backup infrastructure component, it matters for defenders protecting backup and recovery systems. The record does not describe the underlying root cause, so the exact flaw type is unknown.

8.7 CVSS 4.0 High CISA KEV since 28 Apr 2025 EPSS 2.3% · top 17.4%
8.7CVSS 4.0 base score
2.3%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw allows authenticated remote code execution on backup infrastructure and is confirmed exploited in CISA KEV, though it requires valid credentials and the record lacks root-cause detail.

What it is

Commvault Web Server contains an unspecified vulnerability that a remote, authenticated attacker can use to create and execute webshells on the server. Because it allows code execution on a backup infrastructure component, it matters for defenders protecting backup and recovery systems. The record does not describe the underlying root cause, so the exact flaw type is unknown.

Impact

An attacker with valid credentials gains remote code execution on the Commvault Web Server, enabling persistent webshell access and further compromise of the host and connected backup environment.

Attack surface

Reachable over the network via the Commvault Web Server; the CVSS vector indicates network access with low attack complexity and low privileges required, and no user interaction. Authentication is required, so a valid account is a prerequisite.

Exploitation

Listed in CISA KEV since 2025-04-28, confirming exploitation in the wild; EPSS 30-day probability is 0.0214 (81st percentile). No ransomware campaign use is recorded.

What to do

  • Upgrade to fixed versions 11.36.46, 11.32.89, 11.28.141, or 11.20.217 for Windows and Linux as applicable.
  • Follow the vendor advisory and CISA BOD 22-01 required actions, including discontinuing use if mitigations are unavailable.
  • Restrict and audit access to the Commvault Web Server, limiting it to trusted networks and accounts.
  • Review and rotate credentials for Commvault administrative and service accounts.
  • Monitor for unexpected files or scripts written to web-accessible directories on Commvault servers.

Detection

  • Hunt for newly created or modified files in Commvault web server directories, especially script or webshell-like files.
  • Alert on suspicious child processes spawned by the Commvault web server process.
  • Monitor authentication logs for anomalous or unexpected logins to the Commvault Web Server.
  • Review web server logs for unusual POST requests or requests to newly created script paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-3928 to the Known Exploited Vulnerabilities catalog on 28 April 2025 as "Commvault Web Server Unspecified Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 19 May 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-3928 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2025-34028Commvault Command Center unauthenticated ZIP upload path traversal RCECommvault Command Center Innovation Release accepts unauthenticated uploads of ZIP install packages that are expanded without safe path handling, all…KEVEPSS 98%analysed9.8CVE-2017-18044Commvault CVDataPipe.dll unauthenticated command injectionThe message parsing function in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6 fails to validate an incoming string before passing it t…EPSS 70%analysed9.3CVE-2026-77089Commvault authentication bypass by spoofing vulnerabilityCommand Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance releas…EPSS 0.61%9.2CVE-2026-13737Commvault incorrect authorization vulnerabilityCommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance r…EPSS 0.52%9.2CVE-2026-13738Commvault incorrect authorization vulnerabilityCommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to reso…EPSS 0.63%8.8CVE-2026-77097Commvault missing authentication for critical function vulnerabilityPrivate Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software custome…EPSS 0.47%8.8CVE-2026-77098Commvault sql injection vulnerabilityPrivate Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release…EPSS 0.47%8.8CVE-2026-13739Commvault server-side request forgery (ssrf) vulnerabilityA legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrar…EPSS 0.39%

Source: NIST National Vulnerability Database (record CVE-2025-3928), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.