Authorization Bypass Vulnerability in Commvault Products
CVE-2026-13738
9.2CRITICAL
What is CVE-2026-13738?
Commvault's CommServe has a vulnerability that allows unauthorized command execution due to an authorization bypass. Affected customers are strongly advised to update all installations, including the CommServe, Webserver, Command Center, Media Agents, Clients, and HyperScale X, to the latest maintenance release to mitigate potential security risks.
Affected Version(s)
Commvault Cloud Windows 11.46.0 <= 11.46.9
Commvault Cloud Windows 11.44.0 <= 11.44.10
Commvault Cloud Windows 11.40.0 <= 11.40.62
