CVE-2025-34028: Commvault Command Center Path Traversal Vulnerability
Critical severity, CVSS 10.0. Actively exploited: in CISA KEV since 2025-05-02. EPSS: 97.6% chance of exploitation in the next 30 days.
The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP. This issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436 and also fixed in 11.38.25 with SP38-CU25-434 and SP38-CU25-438.
Affected products
- Commvault Commvault: from 11.38.0, before 11.38.20 (fixed in 11.38.20)
Published 2025-04-22. Last modified 2026-06-17.