A critical vulnerability, CVE-2025-57789, has been identified in Commvault Backup and Replication software prior to version 11.36.60. During the short window between installation and the first administrator login, remote attackers may exploit the default credential to gain administrative control. This issue is limited to the setup phase, before any jobs have been configured. Exploitation of this vulnerability can lead to remote code execution (RCE) via CVE-2025-57790, which is a post-authentication RCE.
References:

