CommVault SystemsCVE-2026-13737
Commvault Cloud: improper authorization
Critical9.2CVE-2026-13737 · Published Aug 11, 2026 · updated Sep 9, 2026
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Commvault Cloud Product | >= 11.46.0, <= 11.46.9 | No fix yet |
| >= 11.44.0, <= 11.44.10 | No fix yet | |
| >= 11.40.0, <= 11.40.62 | No fix yet | |
| >= 11.36.0, <= 11.36.113 | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-863
More CommVault Systems advisories
All CommVault Systems| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | Commvault Cloud: heap buffer overflow | High8.7 | No fix yet |
| Sep 8 | Commvault Cloud: stack buffer overflow | High8.7 | No fix yet |
| Sep 8 | Commvault Cloud: SQL injection | High8.8 | No fix yet |
| Sep 8 | Commvault Cloud: missing authentication | High8.8 | No fix yet |
| Aug 11 | Commvault Cloud: server-side request forgery | High8.8 | No fix yet |
| Aug 11 | Commvault Cloud: improper authorization | Critical9.2 | No fix yet |