Impact
Improper Authorization Validation in CommServe allows a bypass of the intended access control checks for a limited set of command execution operations. By exploiting this flaw, an attacker may trigger privileged commands within the Commvault Cloud environment, compromising confidentiality, integrity and availability. The flaw is a classic access control weakness, reflected in CWE‑863.
Affected Systems
The vulnerability affects the Commvault Cloud platform, including CommServe, Webserver, Command Center, Media Agents, Clients and HyperScale X. All installations of these components that have not applied the resolved maintenance release are affected.
Risk and Exploitability
The CVSS base score of 9.2 classifies the issue as Critical, indicating high impact on confidentiality, integrity and availability. The EPSS score of < 1% indicates a very low probability of exploitation at any given time, but the flaw remains a high‑severity vulnerability. The flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote exploitation via exposed management interfaces such as the web UI or API; an adversary would need network connectivity to those services to exploit the authorization bypass.
OpenCVE Enrichment