MEDIUM
Unauthorized API Access Risk
Published Aug 20, 2025
6.9
MEDIUMCVSS 4.0
EPSS 2.85%
Description
A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.
Affected products
-
- Version 11.32.0StatusaffectedConstraints<=11.32.101
- Version 11.36.0StatusaffectedConstraints<=11.36.59
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://documentation.commvault.com/securityadvisories/CV_2025_08_3.html Vendor Advisory
- https://labs.watchtowr.com/guess-who-would-be-stupid-enough-to-rob-the-same-vault-twice-pre-auth-rce-chains-in-commvault/#wt-2025-0047hardcoded-credentials exploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://documentation.commvault.com/securityadvisories/CV_2025_08_3.html | Vendor Advisory | |
| https://labs.watchtowr.com/guess-who-would-be-stupid-enough-to-rob-the-same-vault-twice-pre-auth-rce-chains-in-commvault/#wt-2025-0047hardcoded-credentials | exploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Commvault
Published Aug 20, 2025
Updated Sep 11, 2025
Reserved Aug 19, 2025
Link CVE-2025-57788
CISA Vulnrichment
Updated Sep 11, 2025