Description
A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center.
Published: 2026-08-11
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in a legacy endpoint of Command Center. It allows an unauthenticated attacker to supply arbitrary target URLs, causing the server to make outbound HTTP requests on the attacker's behalf. This SSRF flaw can be used to probe internal network services, exfiltrate data, or bypass firewalls. The underlying weakness aligns with CWE‑918.

Affected Systems

The affected product is Commvault Cloud’s Command Center. No specific version numbers are provided, but the issue exists in legacy endpoints used by customers of the platform.

Risk and Exploitability

The CVSS score of 8.8 classifies the issue as high severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw is unauthenticated and can be triggered from the network, an attacker with network reach to the Command Center can easily send crafted requests to arbitrary URLs. Exploitation would allow the attacker to reach internal services or any destination accessible from the Command Center’s network.

Generated by OpenCVE AI on August 11, 2026 at 16:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Command Center to the resolved maintenance release that removes the vulnerable legacy endpoint.
  • Restrict outbound network access from the Command Center to only trusted destinations or apply firewall rules to block internal network addresses.
  • Review and harden the Command Center configuration to disable the legacy endpoint if it is still in use.

Generated by OpenCVE AI on August 11, 2026 at 16:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Tue, 11 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center.
Title Server-Side Request Forgery (SSRF)
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Commvault

Published:

Updated: 2026-08-11T14:13:35.906Z

Reserved: 2026-06-29T14:54:17.751Z

Link: CVE-2026-13739

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-11T12:17:38.047

Modified: 2026-08-11T15:17:27.550

Link: CVE-2026-13739

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T16:45:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)