CVE-2026-13737

CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-11 12:17

Updated : 2026-09-09 15:54


NVD link : CVE-2026-13737

Mitre link : CVE-2026-13737

CVE.ORG link : CVE-2026-13737


JSON object : View

Products Affected

commvault

  • commvault
CWE
CWE-863

Incorrect Authorization