CVE-2026-13739

A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-11 12:17

Updated : 2026-09-09 15:55


NVD link : CVE-2026-13739

Mitre link : CVE-2026-13739

CVE.ORG link : CVE-2026-13739


JSON object : View

Products Affected

commvault

  • commvault
CWE
CWE-918

Server-Side Request Forgery (SSRF)