CVE-2026-13737Critical· 9.8▾ MidnightCommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Cen…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
0.5% → 0.5%
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
commvault >= 11.36.0, < 11.36.114commvault >= 11.40.0, < 11.40.63commvault >= 11.44.0, < 11.44.11commvault >= 11.46.0, < 11.46.10Upgrade past the affected range:
commvault 11.46.10Connected by shared product, vendor, weakness, or advisory.
CVE-2026-13738Critical· 9.8CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations
CVE-2026-13739Critical· 9.8A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs
CVE-2026-77089Critical· 9.8Command Center API contained an authentication bypass issue affecting privilege management
CVE-2026-77091High· 7.8DataCube contained a path traversal issue affecting security feature enforcement
CVE-2026-77092Critical· 9.8Content Extractor contained a deserialization of untrusted data issue affecting privilege management
CVE-2026-77097High· 8.2Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability