Command Restriction Bypass
Summary
| CVE | CVE-2026-13737 |
|---|---|
| State | PUBLISHED |
| Assigner | Commvault |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-11 12:17:37 UTC |
| Updated | 2026-08-11 17:17:47 UTC |
| Description | CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X. |
Risk And Classification
Primary CVSS: v4.0 9.2 CRITICAL from 050066fd-a2f9-4f32-ab5d-4c53f48bc333
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.004250000 probability, percentile 0.351970000 (date 2026-08-12)
Problem Types: CWE-863 | CWE-863: Incorrect Authorization | CWE-863 CWE-863 Incorrect Authorization
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 050066fd-a2f9-4f32-ab5d-4c53f48bc333 | Secondary | 9.2 | CRITICAL | CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 9.2 | CRITICAL | CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
HighAttack Requirements
NonePrivileges Required
NoneUser Interaction
NoneConfidentiality
HighIntegrity
HighAvailability
HighSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Commvault | Commvault Cloud | affected 11.46.0 11.46.9 custom | Windows, Linux |
| CNA | Commvault | Commvault Cloud | affected 11.44.0 11.44.10 custom | Windows, Linux |
| CNA | Commvault | Commvault Cloud | affected 11.40.0 11.40.62 custom | Windows, Linux |
| CNA | Commvault | Commvault Cloud | affected 11.36.0 11.36.113 custom | Windows, Linux |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| documentation.commvault.com/securityadvisories/CV_2026_07_8.html | 050066fd-a2f9-4f32-ab5d-4c53f48bc333 | documentation.commvault.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.