← back
CVE-2025-57788mediumobserved exploitationCWE-259

Unauthorized API Access Risk

50Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 6.9epss 2.8%
from disclosure to weapon0 days
Published on NVDAug 20
metasploitAug 19
VulnCheck+3d
exploitation probability
2.8%top 15% of all CVEs
observed exploitation
yesVulnCheck
A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
Commvault · CommCell