Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 11 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Wed, 10 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Commvault before 11.36.60. A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk. | A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk. |
Thu, 21 Aug 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Commvault commvault
|
|
| CPEs | cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Commvault commvault
|
|
| Metrics |
cvssV3_1
|
Thu, 21 Aug 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Commvault
Commvault commcell |
|
| Vendors & Products |
Commvault
Commvault commcell |
Wed, 20 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
ssvc
|
Wed, 20 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 Aug 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized API Access Risk | |
| Weaknesses | CWE-259 | |
| References | ||
| Metrics |
cvssV4_0
|
Wed, 20 Aug 2025 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Commvault before 11.36.60. A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-11T14:02:30.986Z
Reserved: 2025-08-19T00:00:00.000Z
Link: CVE-2025-57788
Updated: 2025-08-20T13:31:22.564Z
Status : Modified
Published: 2025-08-20T04:16:03.590
Modified: 2025-09-10T16:15:40.133
Link: CVE-2025-57788
No data.
OpenCVE Enrichment
Updated: 2025-08-21T12:31:31Z