A critical vulnerability, CVE-2025-57791, has been identified in Commvault Backup and Replication software prior to version 11.36.60. Due to command-line argument injection being passed to authentication components without sufficient sanitization, it is possible to bypass authentication and gain administrative privileges. Exploitation of this vulnerability can lead to remote code execution (RCE) via CVE-2025-57790, which is a post-authentication RCE.
References:

