Commvault Backup Suite Flaws Allow Attackers to Breach On-Prem Deployments

Security researchers at watchTowr Labs have discovered four critical vulnerabilities in Commvault’s enterprise backup and data protection platform, creating two distinct attack chains that allow complete pre-authentication remote code execution (RCE) on vulnerable systems.

The vulnerabilities, disclosed on August 20, 2025, affect Commvault’s backup and replication solutions trusted by major enterprises worldwide.

The flaws enable attackers to bypass authentication and execute arbitrary commands without requiring any valid credentials.

Two Attack Paths Discovered

The research team identified two separate exploit chains, both culminating in full system compromise:

Chain One combines CVE-2025-57791 and CVE-2025-57790, exploiting an argument injection vulnerability in Commvault’s QLogin authentication system alongside a path traversal flaw.

This chain works against any unpatched Commvault instance without environmental prerequisites.

Chain Two leverages CVE-2025-57788 and CVE-2025-57789 to first leak credentials of a low-privileged built-in account, then escalate privileges using a hardcoded encryption key to decrypt the administrator password.

This chain requires that the admin password hasn’t been changed since the initial installation.

Technical Details

The most severe vulnerability (CVE-2025-57791) allows attackers to inject arbitrary arguments into Commvault’s authentication system.

By manipulating the commserver and password parameters in login requests, attackers can bypass authentication entirely and generate valid tokens for the highly privileged localadmin user.

The second critical flaw (CVE-2025-57790) enables attackers to write malicious JSP webshells directly into the application’s webroot through absolute path traversal in QCommand output handling, achieving remote code execution.

Additional vulnerabilities include hardcoded credentials for built-in accounts that can be extracted pre-authentication and a privilege escalation flaw using a hardcoded AES encryption key.

Impact and Affected Systems

The vulnerabilities affect multiple Commvault versions across Linux and Windows platforms:

  • Versions 11.32.0 through 11.32.101 (fixed in 11.32.102)
  • Versions 11.36.0 through 11.36.59 (fixed in 11.36.60)
  • Versions 11.38.20 through 11.38.25 (fixed in 11.38.32)

Given Commvault’s enterprise customer base, including large organizations and managed service providers, these vulnerabilities represent a significant threat to critical backup infrastructure.

Vendor Response and Timeline

Commvault was first notified of the vulnerabilities in April 2025, with the complete disclosure process spanning four months.

The vendor has released security advisories and patches for all affected versions.

Organizations using Commvault solutions should immediately update to the latest patched versions and review their backup infrastructure for signs of compromise.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories