{"id":"CVE-2026-13738","title":"CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations","summary":"CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations.  Software customers upgrade to resolved maintenance release.  Update all Commvault installations, including Commserve, Web…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-863"],"vendor":"commvault","product":"commvault","affected":["commvault >= 11.36.0, < 11.36.114","commvault >= 11.40.0, < 11.40.63","commvault >= 11.44.0, < 11.44.11","commvault >= 11.46.0, < 11.46.10"],"patched":["commvault 11.46.10"],"published":"2026-08-11","updated":"2026-09-11","sourceUpdated":"2026-09-11T14:25:13.003","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-13738","references":[{"url":"https://documentation.commvault.com/securityadvisories/CV_2026_07_9.html","label":"050066fd-a2f9-4f32-ab5d-4c53f48bc333"}],"tags":["nvd"],"epss":0.00628,"epssPercentile":0.48737,"ingestedAt":"2026-09-11T16:45:47.843Z","slug":"CVE-2026-13738","body":"## Overview\n\nCommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations.  Software customers upgrade to resolved maintenance release.  Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.\n\n## Affected\n\n- `commvault >= 11.36.0, < 11.36.114`\n- `commvault >= 11.40.0, < 11.40.63`\n- `commvault >= 11.44.0, < 11.44.11`\n- `commvault >= 11.46.0, < 11.46.10`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `commvault 11.46.10`","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}