What is CVE-2026-13738?
An authorization bypass vulnerability was identified in CommServe, affecting a limited set of command execution operations. All Commvault installations, including CommServe, Webserver, Command Center, Media Agents, Clients, and HyperScale X, must be updated to the resolved maintenance release.
Azərbaycanca: CommServe-də məhdud komanda icra əməliyyatlarına təsir edən avtorizasiya bypass zəifliyi aşkarlanıb. Bu boşluq CommServe, Webserver, Command Center, Media Agents, Clients və HyperScale X daxil olmaqla bütün Commvault qurğularını yeniləməklə aradan qaldırılmalıdır.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What operations does CVE-2026-13738 affect?
This vulnerability is an authorization bypass in CommServe affecting a limited set of command execution operations.
Which components must be updated to resolve CVE-2026-13738?
All Commvault installations must be updated, including CommServe, Webserver, Command Center, Media Agents, Clients, and HyperScale X.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.