Improper access control in Commvault - CVE-2026-13738
Published: August 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute command execution operations without authorization.
The vulnerability exists due to improper access control in CommServe when handling command execution operations. A remote attacker can invoke a limited set of command execution operations to execute command execution operations without authorization.