9.2
CVE-2026-13738
- EPSS 0.53%
- Veröffentlicht 11.08.2026 11:01:39
- Zuletzt bearbeitet 11.08.2026 17:17:47
- CVE-Watchlists
- Unerledigt
Improper Authorization Validation
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerCommvault
≫
Produkt
Commvault Cloud
Default Statusunknown
Version <=
11.46.9
Version
11.46.0
Status
affected
Version <=
11.44.10
Version
11.44.0
Status
affected
Version <=
11.40.62
Version
11.40.0
Status
affected
Version <=
11.36.113
Version
11.36.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.53% | 0.419 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 050066fd-a2f9-4f32-ab5d-4c53f48bc333 | 9.2 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://documentation.commvault.com/securityadvisories/CV_2026_07_9.html