---
id: CVE-2025-3928
title: >-
  Commvault Web Server has an unspecified vulnerability that can be exploited by
  a remote, authenticated attacker
summary: >-
  Commvault Web Server has an unspecified vulnerability that can be exploited by
  a remote, authenticated attacker. According to the Commvault advisory:
  "Webservers can be compromised through bad actors creating and executing
  webshells." Fi…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
vendor: commvault
product: commvault
affected:
  - 'commvault >= 11.20.0, < 11.20.217'
  - 'commvault >= 11.28.0, < 11.28.141'
  - 'commvault >= 11.32.0, < 11.32.89'
  - 'commvault >= 11.36.0, < 11.36.46'
patched:
  - commvault 11.36.46
published: '2025-04-25'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T18:17:13.773'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-3928'
references:
  - url: 'https://documentation.commvault.com/securityadvisories/CV_2025_03_1.html'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-3928
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://www.cisa.gov/news-events/alerts/2025/05/22/advisory-update-cyber-threat-activity-targeting-commvaults-saas-cloud-application-metallic
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://www.commvault.com/blogs/customer-security-update'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://www.commvault.com/blogs/notice-security-advisory-update'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://www.commvault.com/blogs/security-advisory-march-7-2025'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://www.bleepingcomputer.com/news/security/commvault-says-recent-breach-didnt-impact-customer-backup-data/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3928
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - in-the-wild
  - exploit-available
  - kev
exploited: true
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-04-30T03:56:24.936967Z'
epss: 0.02299
epssPercentile: 0.82764
kev: true
kevDateAdded: '2025-04-28'
kevDueDate: '2025-05-19'
kevRansomware: false
ingestedAt: '2026-10-07T18:42:20.876Z'
---

## Overview

Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28.

## Affected

- `commvault >= 11.20.0, < 11.20.217`
- `commvault >= 11.28.0, < 11.28.141`
- `commvault >= 11.32.0, < 11.32.89`
- `commvault >= 11.36.0, < 11.36.46`

## Remediation

Upgrade past the affected range:

- `commvault 11.36.46`
