CyberRota Analysis
AI-GeneratedAn allowlist bypass vulnerability in CommServe permits unauthorized command execution, potentially compromising the integrity and security of affected systems. Organizations utilizing Commvault products, particularly those managing sensitive data or critical infrastructure, should prioritize immediate upgrades to the latest maintenance release to mitigate this critical risk.
CVE
CVE-2026-13737
Severity
CRITICAL
CVSS
9.2
EPSS
0.43%
Original NVD Description
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.