An issue was discovered in Commvault before 11.36.60. A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.
id: CVE-2025-57788
info:
name: Commvault - Unauthorized API Access
author: DhiyaneshDK,watchtow
...