CVE-2026-13738 PUBLISHED

Improper Authorization Validation

Assigner: Commvault
Reserved: 29.06.2026 Published: 11.08.2026 Updated: 11.08.2026

CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.2

Product Status

Vendor Commvault
Product Commvault Cloud
Versions Default: unknown
  • affected from 11.46.0 to 11.46.9 (incl.)
  • affected from 11.44.0 to 11.44.10 (incl.)
  • affected from 11.40.0 to 11.40.62 (incl.)
  • affected from 11.36.0 to 11.36.113 (incl.)

References

Problem Types

  • CWE-863: Incorrect Authorization