Impact
The vulnerability exists in a legacy endpoint of Command Center. It allows an unauthenticated attacker to supply arbitrary target URLs, causing the server to make outbound HTTP requests on the attacker's behalf. This SSRF flaw can be used to probe internal network services, exfiltrate data, or bypass firewalls. The underlying weakness aligns with CWE‑918.
Affected Systems
The affected product is Commvault Cloud’s Command Center. No specific version numbers are provided, but the issue exists in legacy endpoints used by customers of the platform.
Risk and Exploitability
The CVSS score of 8.8 classifies the issue as high severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw is unauthenticated and can be triggered from the network, an attacker with network reach to the Command Center can easily send crafted requests to arbitrary URLs. Exploitation would allow the attacker to reach internal services or any destination accessible from the Command Center’s network.
OpenCVE Enrichment