CVE-2026-13739
Server-Side Request Forgery (SSRF)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center.
| Vendor | commvault |
| Product | commvault cloud |
| Published | Aug 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for commvault commvault cloud
Be the first to know when new unknown vulnerabilities affecting commvault commvault cloud are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Commvault / Commvault Cloud
11.46.0 โค 11.46.9 11.44.0 โค 11.44.10 11.40.0 โค 11.40.62 11.36.0 โค 11.36.113
References
Credits
๐ Peter V., Principal Researcher, CFC Security LTD.