Allowlist Bypass Vulnerability in Commvault's CommServe Product
CVE-2026-13737

9.2CRITICAL

Key Information:

Vendor

Commvault

Vendor
CVE Published:
11 August 2026

What is CVE-2026-13737?

A vulnerability exists in Commvault's CommServe that allows for an allowlist bypass, compromising command execution authorization. Users are advised to upgrade to the latest maintenance release to mitigate this risk. It is crucial to ensure all components, including CommServe, Webserver, Command Center, Media Agents, Clients, and HyperScale X, are updated to the resolved versions to safeguard against potential exploit methods.

Affected Version(s)

Commvault Cloud Windows 11.46.0 <= 11.46.9

Commvault Cloud Windows 11.44.0 <= 11.44.10

Commvault Cloud Windows 11.40.0 <= 11.40.62

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.