CVE-2026-13738
critical · 9.2CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
9.2
CVSS
0.6%
EPSS (exploit prob.)
48th
EPSS percentile
2026-08-11
Published
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weaknesses
CWE-863
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| commvault | commvault | >= 11.36.0, < 11.36.114 |
| commvault | commvault | >= 11.40.0, < 11.40.63 |
| commvault | commvault | >= 11.44.0, < 11.44.11 |
| commvault | commvault | >= 11.46.0, < 11.46.10 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-13738