Skip to content
VulniPulse
Medium6.9Commvault

Medium [CVE-2025-57788] Unauthorized API Access Risk

This medium-severity Commvault advisory covers CVE-2025-57788.

CV_2025_08_3 Published Sep 3, 2025Updated by vendor Aug 19, 2025
Affected products & platforms
CommvaultUnclassified
Open vendor advisory

Android app · Google Play

Monitor future Commvault CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.CVSS Score: 6.9 Medium Commvault Software The following versions are impacted.

Versions that are not listed are either out of support or unaffected. To view version support lifecyle, see Platform Release Schedule and Lifecycles.

Product Platforms Affected Versions Resolved Version Status Commvault Linux, Windows 11.32.0 - 11.32.101 11.32.102 Resolved Commvault Linux, Windows 11.36.0 - 11.36.59 11.36.60 Resolved

Affected versions
  • Affected Versions
  • 11.32.0 - 11.32.101
  • 11.36.0 - 11.36.59

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Fixed versions
  • 11.32.102
  • 11.36.60

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Install the listed maintenance release (or a more recent one) for your feature release: 11.32.102, 11.36.60.

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.