← Vulnerability feed

Vulnerability record · CVE-2025-57791 · published 20 August 2025

CVE-2025-57791: Commvault argument injection vulnerability

Commvault · Commvault

A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input validation. Successful exploitation results in a valid user session for a low privilege role.

6.9 CVSS 4.0 Medium EPSS 22% · top 2.4% CWE-88 · Argument injection
6.9CVSS 4.0 base score
22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input validation. Successful exploitation results in a valid user session for a low privilege role.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-57791 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2025-34028Commvault Command Center unauthenticated ZIP upload path traversal RCECommvault Command Center Innovation Release accepts unauthenticated uploads of ZIP install packages that are expanded without safe path handling, all…KEVEPSS 98%analysed8.7CVE-2025-3928Commvault Web Server webshell upload by authenticated attackerCommvault Web Server contains an unspecified vulnerability that a remote, authenticated attacker can use to create and execute webshells on the serve…KEVEPSS 2.3%analysed9.8CVE-2017-18044Commvault CVDataPipe.dll unauthenticated command injectionThe message parsing function in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6 fails to validate an incoming string before passing it t…EPSS 70%analysed9.3CVE-2026-77089Commvault authentication bypass by spoofing vulnerabilityCommand Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance releas…EPSS 0.61%9.2CVE-2026-13737Commvault incorrect authorization vulnerabilityCommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance r…EPSS 0.52%9.2CVE-2026-13738Commvault incorrect authorization vulnerabilityCommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to reso…EPSS 0.63%8.8CVE-2026-77097Commvault missing authentication for critical function vulnerabilityPrivate Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software custome…EPSS 0.47%8.8CVE-2026-77098Commvault sql injection vulnerabilityPrivate Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release…EPSS 0.47%

Source: NIST National Vulnerability Database (record CVE-2025-57791), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.