Impact
Improper Authorization Validation in CommServe permits an attacker to bypass the intended access control checks for a restricted subset of command execution operations. By exploiting this flaw, an unauthorized user can trigger privileged commands through the management API or web interface, effectively achieving command injection within the Commvault Cloud environment.
Affected Systems
This vulnerability affects the Commvault Cloud platform, specifically the CommServe, Webserver, Command Center, Media Agents, Clients, and HyperScale X components. All installations of these components that have not received the maintenance release are susceptible.
Risk and Exploitability
The CVSS base score of 9.2 classifies the issue as Critical, indicating high impact on confidentiality, integrity, and availability. The EPSS value is currently unavailable, but the lack of a listing in the CISA KEV catalog does not diminish the high risk inherent in the flaw. The attack is achievable remotely through exposed interfaces; an adversary would need network connectivity to the affected services and could execute commands provided the bypass is successful.
OpenCVE Enrichment