Impact
CommServe’s cryptographic signature verification handling is flawed, permitting attackers to forge or modify signed requests and bypass legitimate privilege checks. This flaw can lead to an attacker acquiring higher privileges than allowed, enabling unauthorized actions or access to restricted resources.
Affected Systems
The vulnerability affects CommServe and Web Server components of the Commvault Cloud platform. Specific version information is not listed, so all releases lacking the maintenance update are considered vulnerable.
Risk and Exploitability
With a CVSS score of 8.7 the flaw is high‑severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves manipulating signed requests or tokens to bypass the normal privilege checks, potentially granting system‑level access.
OpenCVE Enrichment