CVE-2025-57789: Vulnerability in Initial Administrator Login Process
Published Aug 20, 2025
·Updated
During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured.
Affected Software
2 affected components
Commvault Commvault<11.36.60
Commvault Commvault<11.36.60
Event History
Aug 20, 2025
CVE Published
via MITRE·03:22 AM
Data Sourced
via MITRE·03:22 AM
DescriptionWeakness
Data Sourced
via NVD·04:16 AM
DescriptionSeverityWeaknessAffected Software
News Published
via The Register·05:03 PM
News Published
via The Register·05:07 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-57789?
CVE-2025-57789 is considered a critical security vulnerability that allows remote attackers to gain administrative control.
2
How do I fix CVE-2025-57789?
To fix CVE-2025-57789, upgrade Commvault to version 11.36.60 or later to mitigate the default credential risk.
3
What versions of Commvault are affected by CVE-2025-57789?
CVE-2025-57789 affects Commvault versions prior to 11.36.60.
4
When does CVE-2025-57789 become exploitable?
CVE-2025-57789 becomes exploitable during the setup phase before the first administrator login.
5
What is the impact of CVE-2025-57789 on Commvault installations?
The impact of CVE-2025-57789 is that attackers can gain full administrative access before any configuration is made.