CVE-2025-34028 - CVE House
Back to Database
Status published Critical CVE-2025-34028

Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal

Vulnerability Description

The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP. This issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436 and also fixed in 11.38.25 with SP38-CU25-434 and SP38-CU25-438.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34028

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Sonny of watchTowr

Affected Vendor

Affected Software

Command Center Innovation Release
Vulnerable Versions:
11.38.0

Timeline

Official Publish: April 22nd, 2025
Last Modified: November 29th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)