Impact
The vulnerability in the Command Center API permits an attacker to bypass authentication controls, allowing unauthorized privileged operations. This flaw can give attackers full administrative control over the affected system, potentially compromising confidentiality, integrity, and availability.
Affected Systems
Commvault Cloud Command Center, the central management component of Commvault Cloud, is impacted. No specific version range is listed in the advisory, but the issue applies to any instance that has not applied the resolved maintenance release referenced by Commvault.
Risk and Exploitability
With a CVSS score of 9.3 the vulnerability is classified as critical. The EPSS score is 0.0033 (less than 1%) and it is not listed in the CISA KEV catalog. The likely attack vector is over the network through the Command Center API; based on the description it is inferred that an attacker could send crafted API requests that bypass authentication, enabling privileged actions without valid credentials.
OpenCVE Enrichment