CVE-2026-13739

8.8

Commvault · Commvault Cloud

A legacy endpoint in the Commvault Cloud Command Center is vulnerable to unauthenticated server-side request forgery (SSRF).

Executive summary

An unauthenticated SSRF vulnerability in the Commvault Cloud Command Center allows attackers to perform unauthorized requests on behalf of the server.

Vulnerability

The application fails to properly validate target URLs in a legacy Command Center endpoint, leading to Server-Side Request Forgery (CWE-918). This flaw is exploitable by unauthenticated attackers.

Business impact

The CVSS score of 8.8 highlights the high risk associated with this SSRF vulnerability. Attackers can leverage the server as a proxy to interact with internal services that are otherwise unreachable from the public internet, potentially leading to data theft or further internal network reconnaissance.

Remediation

Immediate Action: Review the official Commvault security advisory for specific patch instructions and apply the required software updates as soon as they are made available.

Proactive Monitoring: Inspect network logs for unusual outbound traffic patterns originating from the Commvault server, particularly requests directed toward internal network segments.

Compensating Controls: Implement strict network egress filtering on the Commvault server to prevent it from initiating connections to unauthorized internal or external destinations.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This unauthenticated SSRF vulnerability allows for significant internal network exposure. Security teams must ensure their Commvault Cloud environments are updated to the latest supported versions and apply restrictive egress controls to minimize the potential attack surface.