Impact
CommServe contains an allowlist bypass that permits an attacker to execute arbitrary commands on the system. This flaw undermines command execution authorization and can lead to full compromise of the affected host, resulting in loss of confidentiality, integrity and availability.
Affected Systems
Affected are all Commvault installations – CommServe, Webserver, Command Center, Media Agents, Clients and HyperScale X – regardless of product variant. Version information is not specified; applying the latest maintenance release that includes the fix is required.
Risk and Exploitability
The CVSS score of 9.2 indicates a high severity flaw and, while an EPSS score is not available, the description implies a remote attack path via network access to CommServe. The flaw is not listed in the CISA KEV catalog, but the potential for remote code execution makes it a risk worth addressing immediately.
OpenCVE Enrichment