Friday, 22 August

Friday, 22 August2025

Critical Pre-Auth Vulnerabilities in Commvault Let Hackers Achieve RCE Without Logging In

Critical Pre-Auth Vulnerabilities in Commvault Let Hackers Achieve RCE Without Logging In
Security researchers have uncovered four serious pre-authentication exploit chains in Commvault versions earlier than 11.36.60 that enable remote code execution (RCE) without requiring credentials. These flaws include CVE-2025-57788a login mechanism bypassand CVE-2025-57789, which exploits default credentials during initial setup to grant admin privileges. Commvault has issued updates to fix these critical issues.

Subscribe To Our Newsletter.

Full Name
Email