#VU107997 Input validation error in Commvault - CVE-2025-3928
Published: April 28, 2025
Commvault
Commvault
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to an unspecified vulnerability in the Commvault Web Server. A remote non-authenticated attacker can send specially crafted request to the server and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.