PT-2025-17932 · Commvault · Commvault Web Server
CVE-2025-3928
·
Published
2025-02-24
·
Updated
2026-07-19
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Commvault Web Server versions prior to 11.36.46
Commvault Web Server versions prior to 11.32.89
Commvault Web Server versions prior to 11.28.141
Commvault Web Server versions prior to 11.20.217
Description
An unspecified vulnerability in the Commvault Web Server, caused by deficiencies in the input validation mechanism, allows a remote, authenticated attacker to execute arbitrary code. This flaw enables the creation and execution of webshells—scripts that allow attackers to maintain persistent access to a compromised server—to gain unauthorized access to sensitive data. Real-world exploitation has been attributed to state-sponsored threat actors, including Silk Typhoon (HAFNIUM) and Salt Typhoon, who targeted the Azure-hosted Metallic M365 backup SaaS environment in February 2025. These attackers used the flaw to obtain client secrets and service principals, facilitating lateral movement into downstream customer Microsoft 365 environments via hijacked OAuth apps and API-native exfiltration through EWS and MSGraph APIs.
Recommendations
Update to version 11.36.46, 11.32.89, 11.28.141, or 11.20.217 depending on the current installation branch.
As a temporary workaround, disable the web server.
Rotate credentials for application secrets managed by Commvault.
Implement access control policies that restrict authentication to whitelisted IP addresses.
Re-evaluate and restrict permissions assigned to service principals to follow the principle of least privilege.
Conduct a thorough audit of Microsoft login logs to identify unauthorized access or changes.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Commvault Web Server