Critical Commvault Command Center Flaw Enable Attackers to Execute Code Remotely
A critical security flaw has been disclosed in the Commvault Command Center that could allow arbitrary code execution on affected installations.
The vulnerability, tracked as CVE-2025-34028, carries a CVSS score of 9.0 out of a maximum of 10.0.
"A critical security vulnerability has been identified in the Command Center installation, allowing remote attackers to execute arbitrary code without authentication," Commvault said in an advisory published on April 17, 2025. "This vulnerability could lead to a complete compromise of the Command Center environment."
originally posted at 

The Hacker News
Critical Commvault Command Center Flaw Enables Attackers to Execute Code Remotely
Commvault flaw CVE-2025-34028 enables pre-auth SSRF leading to code execution; fix in 11.38.20+ versions.
Stacker News
Critical Commvault Command Center Flaw Enable Attackers to Execute Code Remotely \ stacker news ~security
A critical security flaw has been disclosed in the Commvault Command Center that could allow arbitrary code execution on affected installations. Th...



