CVE-2026-13739
EUVD-2026-5600011.08.2026, 12:17
A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| commvault | commvault | 11.46.0 ≤ 𝑥 ≤ 11.46.9 | CNA |
| commvault | commvault | 11.44.0 ≤ 𝑥 ≤ 11.44.10 | CNA |
| commvault | commvault | 11.40.0 ≤ 𝑥 ≤ 11.40.62 | CNA |
| commvault | commvault | 11.36.0 ≤ 𝑥 ≤ 11.36.113 | CNA |