What is CVE-2026-13737?
CVE-2026-13737 is an allowlist bypass vulnerability in CommServe affecting command execution authorization. This flaw could allow unauthorized command execution. All Commvault installations, including CommServe, Webserver, Media Agents, and Clients, must be updated to the resolved maintenance release.
Azərbaycanca: CVE-2026-13737, CommServe-də əmr icrası avtorizasiyasına təsir edən "allowlist" keçid zəifliyidir. Bu boşluq təsdiqlənməmiş əmrlərin icrasına imkan verə bilər. Bütün Commvault komponentləri, o cümlədən CommServe, Webserver, Media Agent və müştəri tətbiqləri ən son yamaqlanmış versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Where does the CVE-2026-13737 vulnerability exist and what is its impact?
CVE-2026-13737 is an allowlist bypass vulnerability in CommServe affecting command execution authorization. This flaw could allow unauthorized command execution.
Which components need to be updated regarding CVE-2026-13737?
All Commvault installations, including CommServe, Webserver, Media Agents, and Clients, must be updated to the resolved maintenance release.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.