CVE-2026-77097
published 2026-09-08CVE-2026-77097: Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade…
PriorityP347high8.2CVSS 3.1
AVNACLPRNUINSUCNILAH
EPSS
0.26%
17.7th percentile
Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| commvault | commvault | >= 11.36.0 < 11.36.123 | 11.36.123 |
| commvault | commvault | >= 11.40.0 < 11.40.72 | 11.40.72 |
| commvault | commvault | >= 11.44.0 < 11.44.20 | 11.44.20 |
| commvault | commvault | >= 11.46.0 < 11.46.20 | 11.46.20 |
| commvault | commvault_cloud | 11.36.0 – 11.36.122 | — |
| commvault | commvault_cloud | 11.40.0 – 11.40.71 | — |
| commvault | commvault_cloud | 11.44.0 – 11.44.19 | — |
| commvault | commvault_cloud | 11.46.0 – 11.46.19 | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Commvault Cloud up to 11.36.122/11.40.71/11.44.19/11.46.19 Metrics Upload missing authentication
vuldb·2026-09-13·CVSS 8.2
CVE-2026-77097 [HIGH] Commvault Cloud up to 11.36.122/11.40.71/11.44.19/11.46.19 Metrics Upload missing authentication
A vulnerability classified as critical has been found in Commvault Cloud up to 11.36.122/11.40.71/11.44.19/11.46.19. This affects an unknown part of the component Metrics Upload. The manipulation leads to missing authentication.
This vulnerability is uniquely identified as CVE-2026-77097. The attack is possible to be carried out remotely. No exploit exists.
GHSA
Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability.
ghsa_unreviewed·2026-09-08
CVE-2026-77097 [HIGH] CWE-306 Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability.
Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-08
Published