Commvault - Unauthorized API Access
An issue was discovered in Commvault before 11.36.60. A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk. References: https://labs.watchtowr.com/guess-who-would-be-stupid-enough-to-rob-the-same-vault-twice-pre-auth-rce-chains-in-commvault/ https://documentation.commvault.com/securityadvisories/CV_2025_08_3.html
Used 3.9k times · 1 assets checked · domain, subdomain, ipv4