Vulnerability record · CVE-2025-3928 · published 25 April 2025
CVE-2025-3928: Commvault Web Server webshell upload by authenticated attacker
Commvault · Commvault
Commvault Web Server contains an unspecified vulnerability that a remote, authenticated attacker can use to create and execute webshells on the server. Because it allows code execution on a backup infrastructure component, it matters for defenders protecting backup and recovery systems. The record does not describe the underlying root cause, so the exact flaw type is unknown.
Description
Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
high priorityThe flaw allows authenticated remote code execution on backup infrastructure and is confirmed exploited in CISA KEV, though it requires valid credentials and the record lacks root-cause detail.
What it is
Commvault Web Server contains an unspecified vulnerability that a remote, authenticated attacker can use to create and execute webshells on the server. Because it allows code execution on a backup infrastructure component, it matters for defenders protecting backup and recovery systems. The record does not describe the underlying root cause, so the exact flaw type is unknown.
Impact
An attacker with valid credentials gains remote code execution on the Commvault Web Server, enabling persistent webshell access and further compromise of the host and connected backup environment.
Attack surface
Reachable over the network via the Commvault Web Server; the CVSS vector indicates network access with low attack complexity and low privileges required, and no user interaction. Authentication is required, so a valid account is a prerequisite.
Exploitation
Listed in CISA KEV since 2025-04-28, confirming exploitation in the wild; EPSS 30-day probability is 0.0214 (81st percentile). No ransomware campaign use is recorded.
What to do
- Upgrade to fixed versions 11.36.46, 11.32.89, 11.28.141, or 11.20.217 for Windows and Linux as applicable.
- Follow the vendor advisory and CISA BOD 22-01 required actions, including discontinuing use if mitigations are unavailable.
- Restrict and audit access to the Commvault Web Server, limiting it to trusted networks and accounts.
- Review and rotate credentials for Commvault administrative and service accounts.
- Monitor for unexpected files or scripts written to web-accessible directories on Commvault servers.
Detection
- Hunt for newly created or modified files in Commvault web server directories, especially script or webshell-like files.
- Alert on suspicious child processes spawned by the Commvault web server process.
- Monitor authentication logs for anomalous or unexpected logins to the Commvault Web Server.
- Review web server logs for unusual POST requests or requests to newly created script paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-3928 to the Known Exploited Vulnerabilities catalog on 28 April 2025 as "Commvault Web Server Unspecified Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 19 May 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://documentation.commvault.com/securityadvisories/CV_2025_03_1.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-3928 | Third Party AdvisoryUS Government Resource |
| https://www.cisa.gov/news-events/alerts/2025/05/22/advisory-update-cyber-threat-activity-targeting-commvaults-saas-cloud | Third Party AdvisoryUS Government Resource |
| https://www.commvault.com/blogs/customer-security-update | Vendor Advisory |
| https://www.commvault.com/blogs/notice-security-advisory-update | Vendor Advisory |
| https://www.commvault.com/blogs/security-advisory-march-7-2025 | Vendor Advisory |
| https://www.bleepingcomputer.com/news/security/commvault-says-recent-breach-didnt-impact-customer-backup-data/ | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3928 | US Government Resource |
Track CVE-2025-3928 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-3928), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.