Target Industry
Indiscriminate, opportunistic targeting.
Overview
A critical path traversal vulnerability, tracked as CVE-2025-34028, has been identified in Commvault Command Center Innovation Release version 11.38, affecting both Linux and Windows installations. This vulnerability, rated with the maximum CVSS v3.1 score of 10.0, enables unauthenticated remote attackers to upload malicious ZIP files, ultimately leading to remote code execution (RCE) and full compromise of the Command Center environment.
Commvault Command Center is a widely used web-based interface for managing data protection and backup operations. Exploitation of this flaw poses a severe risk to organisations relying on Commvault solutions for critical data management.
Impact
Successful exploitation of CVE-2025-34028 allows attackers to fully compromise the affected Commvault environment, granting them the ability to execute arbitrary code, manipulate configurations, access sensitive backup data, and disrupt operations. This vulnerability is particularly dangerous due to the unauthenticated nature of the exploit, allowing remote attackers to gain control without any prior access.
Affected Products
Affected versions: Commvault Command Center Innovation Release versions 11.38.0 to 11.38.19.
Exploitation
- Exploitable through the /commandcenter/deployWebpackage.do endpoint via a pre-authenticated Server-Side Request Forgery (SSRF)
- Allows the upload of a ZIP archive containing a malicious .JSP file, which can be executed post-deployment
- A Proof-of-Concept (PoC) exploit has been publicly released, increasing the risk of widespread exploitation
Containment, Mitigations & Remediations
Commvault users must upgrade to version 11.38.20 or later immediately.
Threat Landscape
Backup and replication software have increasingly become high-value targets for cyber threat actors. This trend underscores the strategic importance of these systems in enterprise environments and the consequent risk posed by vulnerabilities within them.
Further Information













