#VU123431 Weak password requirements in Commvault
Published: March 3, 2026
Commvault
Commvault
Description
The vulnerability allows an attacker to perform brute-force attack and guess the OTP token.
The vulnerability exists due to the application does not invalidate previously generated One-Time Passwords (OTPs) codes during authentication. A remote attacker can generate multiple OTP codes and brute-force them, increasing potential success rates.