Junglewise Threat Intelligence

CVE-2026-13738: Commvault CommServe authorization bypass in command execution

CVE-2026-13738 · Severity: critical · CVSS 9.8 · Published 2026-08-11

Technologies: Commvault CommServe. Vendors: Commvault.

Executive brief

Commvault CommServe, a centralized backup and disaster recovery management platform, contains an authorization bypass vulnerability that allows attackers to execute commands without proper authorization checks. An attacker exploiting this flaw could gain unauthorized control over backup operations, potentially leading to data theft, corruption, or denial of service across an organization's entire backup infrastructure.

Technical details

The vulnerability is an improper authorization validation flaw in Commvault CommServe affecting a limited set of command execution operations. The authorization bypass allows attackers to bypass access controls on sensitive commands without requiring valid credentials or elevated privileges. This is a network-reachable vulnerability that does not require user interaction or prior authentication. An attacker can exploit this to execute arbitrary commands within the scope of the vulnerable operations, potentially compromising the confidentiality, integrity, and availability of backed-up data. Patches are available in resolved maintenance releases: versions 11.46.10, 11.44.11, 11.40.63, and 11.36.114 or higher.

Affected products

  • Commvault CommServe 11.36.0–11.36.113, 11.40.0–11.40.62, 11.44.0–11.44.10, 11.46.0–11.46.9

Timeline

  • 2026-08-11: disclosed

References

Related threats