Description
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
Published: 2026-08-11
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper Authorization Validation in CommServe allows a bypass of the intended access control checks for a limited set of command execution operations. By exploiting this flaw, an attacker may trigger privileged commands within the Commvault Cloud environment, compromising confidentiality, integrity and availability. The flaw is a classic access control weakness, reflected in CWE‑863.

Affected Systems

The vulnerability affects the Commvault Cloud platform, including CommServe, Webserver, Command Center, Media Agents, Clients and HyperScale X. All installations of these components that have not applied the resolved maintenance release are affected.

Risk and Exploitability

The CVSS base score of 9.2 classifies the issue as Critical, indicating high impact on confidentiality, integrity and availability. The EPSS score of < 1% indicates a very low probability of exploitation at any given time, but the flaw remains a high‑severity vulnerability. The flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote exploitation via exposed management interfaces such as the web UI or API; an adversary would need network connectivity to those services to exploit the authorization bypass.

Generated by OpenCVE AI on August 13, 2026 at 04:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all Commvault installations, including CommServe, Webserver, Command Center, Media Agents, Clients and HyperScale X, to the resolved maintenance release.
  • Review and reinforce role‑based access controls and enforce least privilege to reduce the risk of other authorization gaps.
  • Monitor management interfaces for unauthorized command execution attempts and anomalous activity to detect potential exploitation.

Generated by OpenCVE AI on August 13, 2026 at 04:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Commvault
Commvault commvault
Vendors & Products Commvault
Commvault commvault

Thu, 13 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 11 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 11 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
Title Improper Authorization Validation
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Commvault Commvault
cve-icon MITRE

Status: PUBLISHED

Assigner: Commvault

Published:

Updated: 2026-08-11T16:48:34.748Z

Reserved: 2026-06-29T14:54:16.684Z

Link: CVE-2026-13738

cve-icon Vulnrichment

Updated: 2026-08-11T16:48:25.964Z

cve-icon NVD

Status : Received

Published: 2026-08-11T12:17:37.923

Modified: 2026-08-11T17:17:47.660

Link: CVE-2026-13738

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:45:03Z

Weaknesses