Vulnerability Intelligence Report
Command Restriction Bypass
CVE-2026-13737
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
No Active Exploit Signals
CVSS Base Score
9.2
CRITICAL
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-863 ↗CWE-863: Incorrect Authorization
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Commvault | Commvault Cloud | 11.46.0 <= 11.46.9 (affected), 11.44.0 <= 11.44.10 (affected), 11.40.0 <= 11.40.62 (affected), 11.36.0 <= 11.36.113 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Commvault Systems Inc. · Vendor · USA |
| Reserved | 2026-06-29T14:54:15 |
| Published | 2026-08-11T11:01:38 |
| Last Updated | 2026-08-11T16:49:09 |
Community Chatter & Buzz