{"id":"CVE-2026-13739","title":"A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs","summary":"A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs.  Software customers upgrade to resolved maintenance release.  Update Comm…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-918"],"vendor":"commvault","product":"commvault","affected":["commvault >= 11.36.0, < 11.36.114","commvault >= 11.40.0, < 11.40.63","commvault >= 11.44.0, < 11.44.11","commvault >= 11.46.0, < 11.46.10"],"patched":["commvault 11.46.10"],"published":"2026-08-11","updated":"2026-09-09","sourceUpdated":"2026-09-09T15:55:22.207","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-13739","references":[{"url":"https://documentation.commvault.com/securityadvisories/CV_2026_07_5.html","label":"050066fd-a2f9-4f32-ab5d-4c53f48bc333"}],"tags":["nvd"],"epss":0.0039,"epssPercentile":0.32998,"ingestedAt":"2026-09-09T16:14:05.512Z","slug":"CVE-2026-13739","body":"## Overview\n\nA legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs.  Software customers upgrade to resolved maintenance release.  Update Command Center.\n\n## Affected\n\n- `commvault >= 11.36.0, < 11.36.114`\n- `commvault >= 11.40.0, < 11.40.63`\n- `commvault >= 11.44.0, < 11.44.11`\n- `commvault >= 11.46.0, < 11.46.10`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `commvault 11.46.10`","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}