vulnerability

Commvault Web Server: CVE-2025-57789: Storing Passwords in a Recoverable Format

Severity
5
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:N)
Published
Aug 20, 2025
Added
Aug 20, 2025
Modified
Aug 20, 2025

Description

An issue was discovered in Commvault before 11.36.60. During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured.

Solution

commvault-web-server-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.