An issue was discovered in Commvault before 11.36.60. A...
Moderate severity
Unreviewed
Published
Aug 20, 2025
to the GitHub Advisory Database
•
Updated Aug 21, 2025
Description
Published by the National Vulnerability Database
Aug 20, 2025
Published to the GitHub Advisory Database
Aug 20, 2025
Last updated
Aug 21, 2025
An issue was discovered in Commvault before 11.36.60. A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input validation. Successful exploitation results in a valid user session for a low privilege role.
References