---
id: CVE-2026-13737
title: >-
  CommServe contained an allowlist bypass vulnerability affecting command
  execution authorization
summary: >-
  CommServe contained an allowlist bypass vulnerability affecting command
  execution authorization.  Software customers upgrade to resolved maintenance
  release. Update all Commvault installations, including Commserve, Webserver,
  Command Cen…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-863
vendor: commvault
product: commvault
affected:
  - 'commvault >= 11.36.0, < 11.36.114'
  - 'commvault >= 11.40.0, < 11.40.63'
  - 'commvault >= 11.44.0, < 11.44.11'
  - 'commvault >= 11.46.0, < 11.46.10'
patched:
  - commvault 11.46.10
published: '2026-08-11'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T15:54:24.553'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13737'
references:
  - url: 'https://documentation.commvault.com/securityadvisories/CV_2026_07_8.html'
    label: 050066fd-a2f9-4f32-ab5d-4c53f48bc333
tags:
  - nvd
epss: 0.00522
epssPercentile: 0.41793
ingestedAt: '2026-09-09T16:14:05.512Z'
---

## Overview

CommServe contained an allowlist bypass vulnerability affecting command execution authorization.  Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.

## Affected

- `commvault >= 11.36.0, < 11.36.114`
- `commvault >= 11.40.0, < 11.40.63`
- `commvault >= 11.44.0, < 11.44.11`
- `commvault >= 11.46.0, < 11.46.10`

## Remediation

Upgrade past the affected range:

- `commvault 11.46.10`
