Summary
CVE-2026-13737 is a command restriction (allowlist) bypass vulnerability in the CommServe component of Commvault. Improper authorization of command execution allows unauthorized commands to run on affected systems. It is rated Critical (CVSS v4.0 base score 9.2).
Technical details
- Root cause: The CommServe component contains an allowlist bypass affecting the authorization of command execution (CWE-863: Incorrect Authorization).
- Trigger conditions: An attacker evades the command authorization/allowlist control to have commands executed that should be restricted.
- Attack vector: Network (AV:N); no privileges (PR:N) or user interaction (UI:N) are required, though attack complexity is high (AC:H).
- Impact: Unauthorized command execution with high impact to confidentiality, integrity, and availability of the affected component.
Affected software
- Commvault 11.46.0 through 11.46.9 (Linux, Windows)
- Commvault 11.44.0 through 11.44.10 (Linux, Windows)
- Commvault 11.40.0 through 11.40.62 (Linux, Windows)
- Commvault 11.36.0 through 11.36.113 (Linux, Windows)
Severity
CVSS v4.0 base score: 9.2 (Critical)
Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: Upgrade to a fixed maintenance release — 11.46.10, 11.44.11, 11.40.63, or 11.36.114 (or later) for the corresponding branch. Per the vendor, update all Commvault components: CommServe, Webserver, Command Center, Media Agents, Clients, and HyperScale X. Verify versions in Command Center under Manage/Infrastructure > Servers.
- If no patch: Restrict network access to CommServe and Commvault management interfaces to trusted administrative networks until upgrades are applied.

