CVE-2026-13737 PUBLISHED

Command Restriction Bypass

Assigner: Commvault
Reserved: 29.06.2026 Published: 11.08.2026 Updated: 11.08.2026

CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.2

Product Status

Vendor Commvault
Product Commvault Cloud
Versions Default: unknown
  • affected from 11.46.0 to 11.46.9 (incl.)
  • affected from 11.44.0 to 11.44.10 (incl.)
  • affected from 11.40.0 to 11.40.62 (incl.)
  • affected from 11.36.0 to 11.36.113 (incl.)

References

Problem Types

  • CWE-863: Incorrect Authorization