PT-2026-70106 · Commvault · Media Agents+4
CVE-2026-13738
·
Published
2026-08-11
·
Updated
2026-08-11
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CommServe (affected versions not specified)
Description
An authorization bypass exists affecting a limited set of command execution operations. This issue allows an attacker to bypass security checks when executing specific commands.
Recommendations
Upgrade to the resolved maintenance release.
Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients, and HyperScale X.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Commserve
Command Centre
Hyperscale X
Media Agents
Vwebserver