CVE-2026-77098
published 2026-09-08CVE-2026-77098: Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update…
PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.47%
37.8th percentile
Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| commvault | commvault | >= 11.36.0 < 11.36.123 | 11.36.123 |
| commvault | commvault | >= 11.40.0 < 11.40.72 | 11.40.72 |
| commvault | commvault | >= 11.44.0 < 11.44.20 | 11.44.20 |
| commvault | commvault | >= 11.46.0 < 11.46.20 | 11.46.20 |
| commvault | commvault_cloud | 11.36.0 – 11.36.122 | — |
| commvault | commvault_cloud | 11.40.0 – 11.40.71 | — |
| commvault | commvault_cloud | 11.44.0 – 11.44.19 | — |
| commvault | commvault_cloud | 11.46.0 – 11.46.19 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Commvault Cloud up to 11.36.122/11.40.71/11.44.19/11.46.19 Database Operations sql injection
vuldb·2026-09-13·CVSS 9.8
CVE-2026-77098 [CRITICAL] Commvault Cloud up to 11.36.122/11.40.71/11.44.19/11.46.19 Database Operations sql injection
A vulnerability was found in Commvault Cloud up to 11.36.122/11.40.71/11.44.19/11.46.19 and classified as critical. The impacted element is an unknown function of the component Database Operations. Executing a manipulation can lead to sql injection.
This vulnerability is tracked as CVE-2026-77098. The attack can be launched remotely. No exploit exists.
GHSA
Private Metrics Server contained an SQL injection condition affecting database operations.
ghsa_unreviewed·2026-09-08
CVE-2026-77098 [HIGH] CWE-89 Private Metrics Server contained an SQL injection condition affecting database operations.
Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-08
Published