Summary
CVE-2026-13738 is an improper authorization validation (CWE-863) vulnerability in Commvault’s CommServe component. Affecting Commvault deployments on Windows and Linux, it allows an unauthorized actor to bypass authorization checks on a limited set of command execution operations. Commvault rates the issue Critical, with a CVSS 4.0 base score of 9.2.
Technical details
- Root cause: CommServe failed to properly validate user permissions for a limited set of command execution operations (improper authorization validation, CWE-863).
- Trigger conditions: According to the vendor, the flaw is exploitable over the network with no privileges and no user interaction required (PR:N, UI:N); the CVSS vector indicates high attack complexity (AC:H).
- Attack vector: Network (AV:N).
- Impact: High impact to confidentiality, integrity, and availability of the affected system (VC:H/VI:H/VA:H).
Affected software
- Commvault (Windows, Linux) 11.46.0 – 11.46.9
- Commvault (Windows, Linux) 11.44.0 – 11.44.10
- Commvault (Windows, Linux) 11.40.0 – 11.40.62
- Commvault (Windows, Linux) 11.36.0 – 11.36.113
Severity
CVSS 4.0 base score: 9.2 (Critical)
Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: Upgrade to a resolved maintenance release for your release train: 11.46.10+, 11.44.11+, 11.40.63+, or 11.36.114+. Update all components, including CommServe, WebServer, Command Center, Media Agents, Clients, and HyperScale X installations.
- Verify patching: In Command Center, navigate to Manage > Servers, filter by role, and confirm all systems run the fixed version or newer.
- If no patch can be applied immediately: Restrict network access to CommServe and management interfaces to trusted administrative networks until the upgrade is completed.

