CVE-2025-57788: Commvault

Medium severity, CVSS 6.5. EPSS: 7.8% chance of exploitation in the next 30 days.

A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.

Affected products

  • Commvault Commvault: before 11.36.60 (fixed in 11.36.60)

Published 2025-08-20. Last modified 2026-06-17.