CVE-2026-13737
Received
Received - Intake
Allowlist Bypass in CommServe Leading to Command Execution
Vulnerability report for CVE-2026-13737, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-11
Last updated on: 2026-08-11
Assigner: Commvault
Description
Description
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| commvault | commserve | From 11.36.114 (inc) to 11.46.10 (exc) |
| commvault | webserver | From 11.36.114 (inc) to 11.46.10 (exc) |
| commvault | command_center | From 11.36.114 (inc) to 11.46.10 (exc) |
| commvault | media_agents | From 11.36.114 (inc) to 11.46.10 (exc) |
| commvault | clients | From 11.36.114 (inc) to 11.46.10 (exc) |
| commvault | hyperscale_x | From 11.36.114 (inc) to 11.46.10 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |