CyberRota Analysis
AI-GeneratedAn authorization bypass vulnerability in CommServe allows unauthorized command execution, potentially compromising system integrity and data security. Organizations using Commvault products, particularly those managing sensitive data, should prioritize immediate upgrades to the latest maintenance release to mitigate this critical risk.
CVE
CVE-2026-13738
Severity
CRITICAL
CVSS
9.2
EPSS
0.53%
Original NVD Description
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.