An issue was discovered in Commvault before 11.36.60. A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.
The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.