CVE-2026-13737
9.2
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Commvault | Commvault Cloud | 11.46.0 <= 11.46.9 | affected |
| Commvault | Commvault Cloud | 11.44.0 <= 11.44.10 | affected |
| Commvault | Commvault Cloud | 11.40.0 <= 11.40.62 | affected |
| Commvault | Commvault Cloud | 11.36.0 <= 11.36.113 | affected |
Weaknesses
- CWE-863: Incorrect Authorization
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.