Commvault fixes critical Command Center issue after flaw finder alert

An update that fixed a critical flaw in data protection biz Commvault’s Command Center was initially not available to a significant user subset – those testing out a free trial version of the product. That is, until a security researcher pointed out the problem.

Commvault offers a suite of tools for data security. Command Center is a dashboard bundled with several other tools that give customers a simple visual view of the data they’re trying to protect. Last week, the Cybersecurity and Infrastructure Security Agency warned that the issue, CVE-2025-34028, was under active exploitation, giving it the highest possible CVSS 10 severity ranking.

The flaw earned its high ranking because it was a path traversal bug that allowed an attacker to get remote code execution privileges on the system by sending ZIP files that contained malicious .jsp files. A security team at watchTowr Labs spotted the flaw last month, and CISA warned Windows and Linux users to update to the latest version of Commvault Command Center, which was supposed to fix the issue.

But according to respected former CERT security analyst Will Dorman, the updates didn’t work for everyone.

Worse, it appeared to Dorman, who was using a free unlicensed version of Command Center, that he had the right version number to fix the flaw – meaning a fastidious updater with an eagle eye for details might think they were protected. But then he tested it.

“It seems that the VM that I have is 11.38.25, which contains the fix for CVE-2025-34028,” he wrote on Mastodon. “EXCEPT the exploit for CVE-2025-34028 still works against it.”

Dormand explained that, in fact, the updated Command Center was only protected after he installed additional updates, which were extremely difficult for him to find, download, and install.

“I talked to them on the phone, and I said, ‘Hey, you guys should really update your advisory, because the current advisory indicates that 11.3, 8.20, is fixed now,'” he told The Register.

“On May 6, they updated the advisory to say, ‘Well, if you’re at 11 point 3.20, you need these two additional updates. Or if you’re on 11.3825 you need these two additional updates.'”

Then Dorman spoke to Commvault the following day, and he claims it turns out to be a question of money – even when there’s a CVSS 10 flaw being actively attacked. Users of the free version weren’t getting updates for a month, he added.

Dormann praised the company for not only getting back to him so quickly but having engineers on the phone keen to solve this in less than a day.

“I was on the phone with them, they did not mention that there was a 30 day waiting period,” he told us.

“But what they ended up doing is, while I was actually live on the phone with them, they changed that on May 7, so that people that got their copy of [Command Center] through Azure or AWS or anything related to that, they would be able to download the latest copy of the software.

“I’m quite confident that they did a fine job of picking up the vulnerability. The problem that I see with all of this is if anybody’s using an unlicensed version that they got through Azure or AWS, they kind of have to jump through some hoops to get the updated version of the software.”

Dorman’s use of the free unlicensed version of Command Center meant he was not able to get access to patches on the same timeline as paying customers. Thanks to Dorman’s attention, Commvault has now changed that policy permanently.

“For our licensed customers, as soon as the patch is available, customers are notified and can deploy the patch at any time or it will be automatically patched on a preset schedule,” a spokesperson for Commvault explained to The Register.

“For users testing out an unlicensed, free trial version, updates are released every 30 days. We previously had not made intermittent patches available to unlicensed, free trial versions before the next 30-day release hit. Going forward, all users, both licensed and those using the free trial, can access and deploy the patch at any time.”

watchTowr had no comment at time of going to press. ®

Iain Thomson
Read More

Latest

More Splatoon 3 Songs Have Been Added To Nintendo Music Today

MusicA side order of music by Liam DoolanTue 7th...

Amanda Bynes on New Song “Girlfriend” Inspiration

Music Amanda Bynes Reveals Inspiration Behind New Song “Girlfriend”Bring...

Me Gusta Fest Rebranded to Sublime Fest After Cypress Hill Drops Out

Music Photo Credit: Sublime FestMusic Music festival Me Gusta...

Pressure mounts on UK government to ban Kanye West after festival backlash

Music The British government was under growing pressure on...

Newsletter

Don't miss

More Splatoon 3 Songs Have Been Added To Nintendo Music Today

MusicA side order of music by Liam DoolanTue 7th...

Amanda Bynes on New Song “Girlfriend” Inspiration

Music Amanda Bynes Reveals Inspiration Behind New Song “Girlfriend”Bring...

Me Gusta Fest Rebranded to Sublime Fest After Cypress Hill Drops Out

Music Photo Credit: Sublime FestMusic Music festival Me Gusta...

Pressure mounts on UK government to ban Kanye West after festival backlash

Music The British government was under growing pressure on...

Queen Latifah Returns to Host the 2026 American Music Awards

MusicThe star last hosted the ceremony 30 years...

The Vogue Business Funding Tracker

Introducing the Vogue Business Funding Tracker, a running list highlighting the most notable and intriguing investment and M&A activity in fashion and beauty. From emerging disruptors to legacy giants undergoing major changes, we spotlight the deals that are shifting the dynamics of the sectors we cover, including fashion, beauty, tech and sustainability. April 2026 Icicle

Family Business? Tee Grizzley Reacts After His Mom Accuses Him Of Leaving Her To Struggle (PHOTOS)

Y’all… it looks like some family tension might be brewing behind the scenes involving Tee Grizzley and his mom. What seemed like a regular social media post quickly turned into something deeper. And now, folks are side-eyeing the situation and wondering what’s really going on. RELATED: Tee Grizzley Shares A Message For Artists After His

SoE necessary but not sufficient, business leaders say

PE­TER CHRISTO­PHER Se­nior Mul­ti­me­dia Re­porter pe­ter.christo­pher@guardian.co.tt Heavy hand­ed but nec­es­sary giv­en the state of crime in T&T. This was a com­mon as­sess­ment from var­i­ous busi­ness groups when asked for their per­spec­tive on the lat­est de­c­la­ra­tion of a state of emer­gency in the coun­try. The T&T Cham­ber of In­dus­try and Com­merce, in a re­leased is­sued yes­ter­day