Threat Advisory

Commvault Enterprise Flaw Lets Attackers Bypass Authorization Checks

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting Commvault Cloud versions These Commvault command execution flaws affect multiple software branches have been identified in Commvault Cloud. These flaws allow remote attackers to bypass authorization checks and forge server requests, impacting critical business data. Affected software versions include the 11.36, 11.40, 11.44, and 11.46 releases on both Windows and Linux operating systems.

CVE-2026-13737 (CVSS 9.2 — Critical): CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Remote attackers can exploit this flaw to gain unauthorized access to core backup infrastructure.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting Commvault Cloud versions These Commvault command execution flaws affect multiple software branches have been identified in Commvault Cloud. These flaws allow remote attackers to bypass authorization checks and forge server requests, impacting critical business data. Affected software versions include the 11.36, 11.40, 11.44, and 11.46 releases on both Windows and Linux operating systems.

CVE-2026-13737 (CVSS 9.2 — Critical): CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Remote attackers can exploit this flaw to gain unauthorized access to core backup infrastructure.[emaillocker id="1283"]

CVE-2026-13738 (CVSS 9.2 — Critical): This vulnerability involves improper authorization validation within the CommServe component, allowing remote attackers to forge server requests and issue unauthorized network requests to internal resources.

CVE-2026-13739 (CVSS 8.8 — High): The Command Center module is impacted by a Server-Side Request Forgery (SSRF) vulnerability, enabling unauthenticated attackers to force the server to issue unauthorized network requests to internal resources.

These vulnerabilities collectively present significant risk for organizations globally relying on Commvault to secure critical business data.

RECOMMENDATION:

We recommend you to update Commvault Cloud to version 11.46.10, 11.44.11, 11.40.63, or 11.36.114.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu