Weak password requirements in Commvault - #VU123431
Published: March 3, 2026
Commvault
Detailed vulnerability description
The vulnerability allows an attacker to perform brute-force attack and guess the OTP token.
The vulnerability exists due to the application does not invalidate previously generated One-Time Passwords (OTPs) codes during authentication. A remote attacker can generate multiple OTP codes and brute-force them, increasing potential success rates.