Executive brief
Commvault CommServe, a core backup and disaster recovery management platform used by enterprises to protect critical data, contained a vulnerability that allowed attackers to bypass command execution authorization controls. An unauthenticated remote attacker could exploit this to execute unauthorized commands with elevated privileges, potentially compromising all protected systems and data managed by the platform.
Technical details
The vulnerability is an allowlist bypass affecting command execution authorization in Commvault CommServe. The root cause stems from insufficient validation of command execution requests against the authorization allowlist, enabling attackers to circumvent intended restrictions. This is a network-accessible vulnerability requiring no authentication or user interaction. Successful exploitation allows remote command execution with the privileges of the CommServe service, which typically has broad access to managed infrastructure. Patches are available for affected versions 11.36.0 through 11.46.9, with resolution in versions 11.36.114, 11.44.11, and 11.46.10 or higher.
Affected products
- Commvault CommServe 11.36.0 - 11.36.113, 11.44.0 - 11.44.10, 11.46.0 - 11.46.9
Timeline
- 2026-08-11: disclosed: CVE-2026-13737 published