CVE-2026-13737EPSS p42.4%
CVE-2026-13737CVE-2026-13737
commvault / commvault
Description
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
Scoring
| CVSS | 9.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.52% probability of exploitation · percentile 42.4% · 2026-10-06T12:00:23Z |
| Last modified | 2026-09-09 |