Skip to content
CommVault SystemsCVE-2026-13737

Commvault Cloud: improper authorization

Critical9.2CVE-2026-13737 · Published Aug 11, 2026 · updated Sep 9, 2026

CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.

CommVault Systems advisory

Affected versions

PackageAffectedFixed in
Commvault Cloud
Product
>= 11.46.0, <= 11.46.9No fix yet
>= 11.44.0, <= 11.44.10No fix yet
>= 11.40.0, <= 11.40.62No fix yet
>= 11.36.0, <= 11.36.113No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-863

More CommVault Systems advisories

All CommVault Systems
Advisory
Commvault Cloud: heap buffer overflow
High8.7Sep 8
Commvault Cloud: stack buffer overflow
High8.7Sep 8
Commvault Cloud: SQL injection
High8.8Sep 8
Commvault Cloud: missing authentication
High8.8Sep 8
Commvault Cloud: server-side request forgery
High8.8Aug 11
Commvault Cloud: improper authorization
Critical9.2Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.