CVE-2026-13737: Command Restriction Bypass
Published Aug 11, 2026
·Updated
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
Affected Software
6 affected components
Commvault CommServe
Commvault Webserver
Commvault Command Center
Commvault Media Agents
Commvault Clients
Commvault HyperScale X
Event History
Aug 11, 2026
CVE Published
via MITRE·11:01 AM
Data Sourced
via MITRE·11:01 AM
DescriptionWeakness