Description
A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.
Problem types
CWE-259: Use of Hard-coded Password
Product status
11.32.0
11.36.0
Credits
Sonny and Piotr Bazydlo (@chudyPB) of watchTowr
References
documentation.commvault.com/...yadvisories/CV_2025_08_3.html