• News/
  • https://www.theregister.com/2025/08/20/commvault_bug_chains_patched/

Commvault releases patches for two pre-auth RCE bug chains

The Register
·
Connor Jones
·
Published Aug 20, 2025
·
Updated

Updated Researchers at watchTowr just published working proof-of-concept exploits for two unauthenticated remote code execution bug chains in backup giant Commvault. They reported the four vulnerabilities to Commvault in April, and the vendor released patches on Wednesday. Commvault SaaS is unaffected. All users are advised to apply the available updates, especially since the first of the two chains works against all unpatched instances. The first chain involves two vulnerabilities (CVE-2025-57791 and CVE-2025-57790), an argument injection in CommServe and a path traversal bug respectively. The severity scores for the flaws are not especially concerning on their own, but chained together they become more dangerous. In Commvault's advisory, it describes CVE-2025-57791 as a vulnerability that allows attackers to retrieve a valid user session for a low-privilege role, assigning it a CVSS score of 6.9 (medium severity). In its PoC, watchTowr painted a different view, showing how to gain access to a local admin account. The argument injection bug at the heart of this chain lies in one of Commvault's QCommands. They're used to carry out admin functions, and their use is protected by requiring a valid API token. QLogin is a QCommand that handles authentication, and researchers found that by altering fields in the request to the Login endpoint, they could bypass the need for a password and generate an API token for the local admin user. The second vulnerability in the chain (CVE-2025...

Read full article

Affected Software

1 affected component
Commvault CommServe
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities are discussed in this article?

The article discusses two unauthenticated remote code execution bug chains in Commvault software.

2

What specific product is affected by these vulnerabilities?

The vulnerabilities affect Commvault CommServe.

3

When were the vulnerabilities reported to Commvault?

The vulnerabilities were reported to Commvault in April.

4

Who published the proof-of-concept exploits for the vulnerabilities?

Researchers at watchTowr published the working proof-of-concept exploits.

5

What action has Commvault taken in response to the vulnerabilities?

Commvault has released patches to address the identified vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203