CVE-2026-13737

Summary

CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.

Affected Software

VendorProductVersion RangeStatus
CommvaultCommvault Cloud11.46.0 <= 11.46.9affected
CommvaultCommvault Cloud11.44.0 <= 11.44.10affected
CommvaultCommvault Cloud11.40.0 <= 11.40.62affected
CommvaultCommvault Cloud11.36.0 <= 11.36.113affected

Weaknesses

  • CWE-863: Incorrect Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References