Impact
CommServe's cryptographic signature verification handling is flawed, allowing authorization bypass that can grant higher privileges to an attacker. This flaw enables an attacker to execute actions or access resources beyond the permissions of the authenticated user.
Affected Systems
The vulnerability affects CommServe and Web Server components of the Commvault Cloud platform. Specific version information is not listed, so all releases lacking the maintenance update are considered vulnerable.
Risk and Exploitability
With a CVSS score of 8.7, the flaw is considered high‑severity. No EPSS score is currently available, and the vulnerability is not listed in CISA's KEV catalog. Based on the description, the likely attack vector involves manipulating signed requests or tokens to bypass the normal privilege checks, potentially giving the attacker system‑level access.
OpenCVE Enrichment