CVE-2025-57788
CVE-2025-57788
6.9
MediumPublished:
Last updated:
Source:050066fd-a2f9-4f32-ab5d-4c53f48bc333
Modified
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- None
- User Interaction
- None
- Confidentiality (Vulnerable)
- Low
- Integrity (Vulnerable)
- Low
- Availability (Vulnerable)
- None
- Confidentiality (Subsequent)
- None
- Integrity (Subsequent)
- None
- Availability (Subsequent)
- None
Description
A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.
References
050066fd-a2f9-4f32-ab5d-4c53f48bc333
https://documentation.commvault.com/securityadvisories/CV_2025_08_3.html