Target Industry

Indiscriminate, opportunistic targeting.

Overview

A critical path traversal vulnerability, tracked as CVE-2025-34028, has been identified in Commvault Command Center Innovation Release version 11.38, affecting both Linux and Windows installations. This vulnerability, rated with the maximum CVSS v3.1 score of 10.0, enables unauthenticated remote attackers to upload malicious ZIP files, ultimately leading to remote code execution (RCE) and full compromise of the Command Center environment. 

Commvault Command Center is a widely used web-based interface for managing data protection and backup operations. Exploitation of this flaw poses a severe risk to organisations relying on Commvault solutions for critical data management. 

Impact

Successful exploitation of CVE-2025-34028 allows attackers to fully compromise the affected Commvault environment, granting them the ability to execute arbitrary code, manipulate configurations, access sensitive backup data, and disrupt operations. This vulnerability is particularly dangerous due to the unauthenticated nature of the exploit, allowing remote attackers to gain control without any prior access. 

Affected Products

Affected versions: Commvault Command Center Innovation Release versions 11.38.0 to 11.38.19. 

Exploitation

  • Exploitable through the /commandcenter/deployWebpackage.do endpoint via a pre-authenticated Server-Side Request Forgery (SSRF) 
  • Allows the upload of a ZIP archive containing a malicious .JSP file, which can be executed post-deployment 
  • A Proof-of-Concept (PoC) exploit has been publicly released, increasing the risk of widespread exploitation 

Containment, Mitigations & Remediations

Commvault users must upgrade to version 11.38.20 or later immediately. 

Threat Landscape

Backup and replication software have increasingly become high-value targets for cyber threat actors. This trend underscores the strategic importance of these systems in enterprise environments and the consequent risk posed by vulnerabilities within them. 

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content