CVE-2026-13738: Commvault

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.

Affected products

  • Commvault Commvault: from 11.36.0, before 11.36.114 (fixed in 11.36.114); from 11.40.0, before 11.40.63 (fixed in 11.40.63); from 11.44.0, before 11.44.11 (fixed in 11.44.11); from 11.46.0, before 11.46.10 (fixed in 11.46.10)

Published 2026-08-11. Last modified 2026-09-11.