CVE-2026-13739: Server-Side Request Forgery (SSRF)
Published Aug 11, 2026
·Updated
A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center.
Affected Software
5 affected components
Command Center
Commvault Commvault>=11.36.0<11.36.114
Commvault Commvault>=11.40.0<11.40.63
Commvault Commvault>=11.44.0<11.44.11
Commvault Commvault>=11.46.0<11.46.10
Event History
Aug 11, 2026
CVE Published
via MITRE·11:01 AM
Data Sourced
via MITRE·11:01 AM
DescriptionWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-13739?
CVE-2026-13739 has a risk score of 62, indicating a moderate severity level.
2
How do I fix CVE-2026-13739?
To mitigate CVE-2026-13739, software customers should upgrade to the resolved maintenance release of Command Center.
3
What type of vulnerability is CVE-2026-13739?
CVE-2026-13739 is categorized as a Server-Side Request Forgery (SSRF) vulnerability.
4
What impacts does CVE-2026-13739 have on my system?
CVE-2026-13739 could potentially allow an unauthenticated attacker to manipulate server requests to arbitrary target URLs.
5
When was CVE-2026-13739 published?
CVE-2026-13739 was published on August 11, 2026.