CVE-2025-57788: Commvault
Medium severity, CVSS 6.5. EPSS: 7.8% chance of exploitation in the next 30 days.
A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.
Affected products
- Commvault Commvault: before 11.36.60 (fixed in 11.36.60)
Published 2025-08-20. Last modified 2026-06-17.