LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-34028: Commvault Command Center Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 2, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 23, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-34028 to its Known Exploited Vulnerabilities catalog on May 2, 2025, with a federal patch deadline of May 23, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Commvault Command Center contains a path traversal vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code.

CVE-2025-34028 is a path traversal vulnerability in Commvault Command Center that allows a remote, unauthenticated attacker to execute arbitrary code. Path traversal flaws let attackers reach files or paths outside intended directories; when that access can lead to code execution, the impact is high for any organization that relies on the product for backup and recovery operations.

Because the flaw requires no authentication and can result in remote code execution, it matters for IT and security teams that run Commvault Command Center. Confirm all product-specific details, including exact affected builds and fixed releases, against the vendor advisory before acting.

How it works

The weakness is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). In this class of flaw, user-controlled input that is meant to select a file or path is not sufficiently sanitized. An attacker can insert directory-traversal sequences (commonly “../” style constructs) so that the application resolves a path outside the intended directory tree.

According to the CISA summary, successful abuse of this path traversal in Commvault Command Center can lead to arbitrary code execution by a remote, unauthenticated attacker. Exact request format, parameters, or payload mechanics are not provided in the public summary; treat any exploit details as unconfirmed until verified against the vendor advisory. In general, once an attacker can write or overwrite files in a location the application later executes or interprets, code execution becomes possible.

Am I affected? How to find it in your systems

Commvault Command Center is typically deployed as the web-based management interface for Commvault backup and recovery environments. It often runs on dedicated management servers or appliances that are reachable by administrators and, in some architectures, by other systems that need to interact with the backup platform.

How to remediate

The primary remediation is to apply the vendor-supplied update or mitigation instructions for CVE-2025-34028. CISA’s required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to a remote, unauthenticated path-traversal issue that can lead to code execution.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities can lead to full compromise of the affected host and, depending on the privileges of the Commvault service account, access to backup catalogs, credentials, or stored data. Known ransomware use of this specific CVE is not documented. If you suspect exploitation, isolate the system, preserve logs and memory images, and begin incident-response procedures. You can also run a free exposure scan of your email addresses against known breach data to check whether related credentials have appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCommvault · Command Center
WeaknessCWE-22
Added to CISA KEVMay 2, 2025
Federal patch deadlineMay 23, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities