Description
A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input validation. Successful exploitation results in a valid user session for a low privilege role.
Problem types
CWE-88: Improper Neutralization of Argument Delimiters in a Command
Product status
11.32.0
11.36.0
Credits
Sonny and Piotr Bazydlo (@chudyPB) of watchTowr
References
documentation.commvault.com/...yadvisories/CV_2025_08_1.html