CVE-2026-13738
Received
Received - Intake
Authorization Bypass in CommServe Command Execution
Vulnerability report for CVE-2026-13738, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-11
Last updated on: 2026-08-11
Assigner: Commvault
Description
Description
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| commvault | commserve | From 11.46.10 (inc) |
| commvault | commserve | From 11.44.11 (inc) |
| commvault | commserve | From 11.40.63 (inc) |
| commvault | commserve | From 11.36.114 (inc) |
| commvault | webserver | * |
| commvault | command_center | * |
| commvault | media_agents | * |
| commvault | clients | * |
| commvault | hyperscale_x | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |