CVE-2026-13738

Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
11/08/2026
Last modified:
11/08/2026

Description

CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.