Description
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
Published: 2026-08-11
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper Authorization Validation in CommServe permits an attacker to bypass the intended access control checks for a restricted subset of command execution operations. By exploiting this flaw, an unauthorized user can trigger privileged commands through the management API or web interface, effectively achieving command injection within the Commvault Cloud environment.

Affected Systems

This vulnerability affects the Commvault Cloud platform, specifically the CommServe, Webserver, Command Center, Media Agents, Clients, and HyperScale X components. All installations of these components that have not received the maintenance release are susceptible.

Risk and Exploitability

The CVSS base score of 9.2 classifies the issue as Critical, indicating high impact on confidentiality, integrity, and availability. The EPSS value is currently unavailable, but the lack of a listing in the CISA KEV catalog does not diminish the high risk inherent in the flaw. The attack is achievable remotely through exposed interfaces; an adversary would need network connectivity to the affected services and could execute commands provided the bypass is successful.

Generated by OpenCVE AI on August 11, 2026 at 16:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official maintenance release that resolves the authorization bypass in CommServe.
  • Ensure that all components of the Commvault Cloud stack, including CommServe, Webserver, Command Center, Media Agents, Clients, and HyperScale X, are upgraded to that release.
  • Conduct a post‑upgrade validation, such as a vulnerability scan or penetration test, to confirm that privileged command execution is no longer possible.

Generated by OpenCVE AI on August 11, 2026 at 16:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 11 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
Title Improper Authorization Validation
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Commvault

Published:

Updated: 2026-08-11T16:48:34.748Z

Reserved: 2026-06-29T14:54:16.684Z

Link: CVE-2026-13738

cve-icon Vulnrichment

Updated: 2026-08-11T16:48:25.964Z

cve-icon NVD

Status : Received

Published: 2026-08-11T12:17:37.923

Modified: 2026-08-11T17:17:47.660

Link: CVE-2026-13738

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T16:45:03Z

Weaknesses