PT-2026-70105 · Commvault · Hyperscale X+4

CVE-2026-13737

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CommServe (affected versions not specified)
Description An allowlist bypass issue exists that affects command execution authorization. This flaw allows an attacker to circumvent the predefined list of approved commands, potentially leading to unauthorized command execution on the system.
Recommendations Upgrade to the resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients, and HyperScale X.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13737

Affected Products

Commserve
Command Centre
Hyperscale X
Media Agents
Vwebserver