PT-2025-17932 · Commvault · Commvault Web Server

CVE-2025-3928

·

Published

2025-02-24

·

Updated

2026-07-19

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Commvault Web Server versions prior to 11.36.46 Commvault Web Server versions prior to 11.32.89 Commvault Web Server versions prior to 11.28.141 Commvault Web Server versions prior to 11.20.217
Description An unspecified vulnerability in the Commvault Web Server, caused by deficiencies in the input validation mechanism, allows a remote, authenticated attacker to execute arbitrary code. This flaw enables the creation and execution of webshells—scripts that allow attackers to maintain persistent access to a compromised server—to gain unauthorized access to sensitive data. Real-world exploitation has been attributed to state-sponsored threat actors, including Silk Typhoon (HAFNIUM) and Salt Typhoon, who targeted the Azure-hosted Metallic M365 backup SaaS environment in February 2025. These attackers used the flaw to obtain client secrets and service principals, facilitating lateral movement into downstream customer Microsoft 365 environments via hijacked OAuth apps and API-native exfiltration through EWS and MSGraph APIs.
Recommendations Update to version 11.36.46, 11.32.89, 11.28.141, or 11.20.217 depending on the current installation branch. As a temporary workaround, disable the web server. Rotate credentials for application secrets managed by Commvault. Implement access control policies that restrict authentication to whitelisted IP addresses. Re-evaluate and restrict permissions assigned to service principals to follow the principle of least privilege. Conduct a thorough audit of Microsoft login logs to identify unauthorized access or changes.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-05191
CVE-2025-3928

Affected Products

Commvault Web Server