CVE-2026-13738: Improper Authorization Validation
Published Aug 11, 2026
·Updated
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
Affected Software
5 affected components
Commvault CommServe
Commvault Commvault>=11.36.0<11.36.114
Commvault Commvault>=11.40.0<11.40.63
Commvault Commvault>=11.44.0<11.44.11
Commvault Commvault>=11.46.0<11.46.10
Event History
Aug 11, 2026
CVE Published
via MITRE·11:01 AM
Data Sourced
via MITRE·11:01 AM
DescriptionWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-13738?
CVE-2026-13738 has a risk score of 60, indicating a moderate level of severity.
2
How do I fix CVE-2026-13738?
To fix CVE-2026-13738, users should upgrade to the resolved maintenance release of Commvault.
3
What type of vulnerability is CVE-2026-13738?
CVE-2026-13738 is an improper authorization validation vulnerability that allows an authorization bypass.
4
Which Commvault installations are affected by CVE-2026-13738?
CVE-2026-13738 affects CommServe, Webserver, Command Center, Media Agents, Clients, and HyperScale X installations.
5
When was CVE-2026-13738 published?
CVE-2026-13738 was published on August 11, 2026.