Home/ Blog/ Security news/ Article
Blog · Security news

Critical Commvault flaw lets attackers run blocked commands on the backup control server

Commvault patched CVE-2026-13737, a critical CVSS 9.2 allowlist bypass in CommServe that lets attackers run commands the backup control server should block.

Central backup control server with one security checkpoint barrier lifted open

Commvault has patched a critical flaw in CommServe, the control server that runs a Commvault backup deployment. Tracked as CVE-2026-13737 and rated CVSS 9.2, the bug lets an attacker slip past the allowlist that decides which commands the server is willing to run. If you operate Commvault, updating CommServe is this week's priority.

The fix landed on August 11, 2026, in Commvault's own security advisory CV_2026_07_8. Commvault assigned the CVE itself, so the details below come straight from the vendor.

What CVE-2026-13737 actually is

CommServe is the brain of a Commvault environment. It coordinates jobs across media agents and clients, and it can run commands as part of that orchestration. Those commands are supposed to be fenced in by an allowlist, a fixed set of what is permitted. The vendor's description is terse, but the mechanics are narrow: the check that decides whether a command is authorized to run can be sidestepped, so an operation the server ought to refuse can go through instead.

The weakness is classed as CWE-863, incorrect authorization. Commvault's own severity breakdown scores it as reachable over the network, needing neither privileges nor any action from a user, but carrying high attack complexity, and with full impact on the affected system's confidentiality, integrity, and availability. High complexity means it is not a trivial one-shot, not that it is safe to ignore.

Affected versions and the fix for each

The flaw spans four release lines on both Linux and Windows, and each carries its own fixed maintenance build. Find your deployment in the table and move to the build listed beside it; anything below that build in the same line is exposed.

Release lineAffected versionsFixed in
11.4611.46.0 to 11.46.911.46.10
11.4411.44.0 to 11.44.1011.44.11
11.4011.40.0 to 11.40.6211.40.63
11.3611.36.0 to 11.36.11311.36.114
CVE-2026-13737: affected Commvault version families and the fixed maintenance release for each (Linux and Windows).

Commvault stresses updating every part of the deployment, not just the control server itself. The Command Center and Web Server, plus every Media Agent, each Client, and the HyperScale X appliances, all take the maintenance release too, so a patch plan that stops at CommServe leaves gaps.

Why this one matters more than the score alone

Backup systems are the part of the network attackers try to reach before they pull the trigger. Ransomware crews delete or corrupt backups first, so a victim cannot recover without paying, and CommServe is the single console that governs the whole backup fabric. A bug that lets commands run past the authorization gate on that host is exactly the kind of primitive an intruder wants once inside. Commvault has been here before: several of its 2025 flaws were reported to have been chained into pre-authentication remote code execution and drew active attention, keeping its products high on attacker target lists.

Is it being exploited?

As of the advisory's publication on August 11, 2026, Commvault reports no known exploitation, and no public proof-of-concept has surfaced. That is the current state, not a guarantee. The gap between a vendor advisory and a working exploit for widely deployed backup software has been measured in days before, so treat the quiet window as time to patch, not a reason to wait.

Patch now, then hunt on CommServe

Three steps, in order:

  • Update to the fixed build for your line on every Commvault role, not the control server alone. The vendor is explicit that the whole deployment, appliances included, needs the maintenance release.

  • Get CommServe off any broad network. The management plane of a backup platform has no business facing the internet, and even on the internal network it should answer only to the hosts that genuinely need it. Tightening that reachability blunts a network-borne bug regardless of the patch state.

  • Hunt for unexpected command execution. Review the control server for commands and child processes that its backup services did not legitimately launch, and extend that watch to the media agents. If you run host monitoring on that server, alert on anomalous processes spawned by Commvault services rather than trusting the application's own allowlist alone.

Backups are only as trustworthy as the server that controls them. Patching CommServe keeps the one system you fall back on from becoming the one an attacker turns against you.

Topics

Frequently asked questions

What is CVE-2026-13737?

CVE-2026-13737 is a critical authorization bypass in Commvault's CommServe server, rated CVSS 9.2. It defeats the allowlist that restricts command execution, letting commands run that the server should block. Commvault disclosed and patched it on August 11, 2026.

Which Commvault versions are affected and fixed?

It affects the 11.36, 11.40, 11.44, and 11.46 lines on Linux and Windows. The fixes are 11.36.114, 11.40.63, 11.44.11, and 11.46.10. Commvault advises updating every component, including CommServe, the Web Server, Command Center, Media Agents, Clients, and HyperScale X.

Is CVE-2026-13737 being exploited?

Commvault's advisory reports no known exploitation as of publication on August 11, 2026, and no public proof-of-concept has appeared. The score lists high attack complexity, but backup control servers are high-value targets, so patching quickly is still the right call.

Does exploitation require authentication?

Commvault's CVSS vector lists no required privileges and no user interaction over the network, though with high attack complexity. The advisory does not detail further preconditions, so treat internet-exposed or broadly reachable CommServe hosts as the highest priority.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.