Executive brief
Commvault's Private Metrics Server is a component used to collect and upload performance and health metrics for cloud-based infrastructure management. The software contains a missing authentication check that allows unauthenticated attackers to upload metrics, potentially disrupting service availability and degrading operational visibility across managed systems. Organizations using affected versions must upgrade immediately to restore proper access controls.
Technical details
The vulnerability is an authentication bypass (missing authentication condition) in the metrics upload functionality of Commvault's Private Metrics Server. The flaw allows unauthenticated requests to the metrics upload endpoint, leading to denial of service through invalid or malicious metric submissions that can impact service availability. The vulnerability affects Commvault versions 11.36.0–11.36.122, 11.40.0–11.40.71, 11.44.0–11.44.19, and 11.46.0–11.46.19 on Linux and Windows platforms. Patches are available in versions 11.36.123, 11.40.72, 11.44.20, 11.46.20 and higher; customers should upgrade to the appropriate resolved maintenance release for their version track.
Affected products
- Commvault Commvault 11.36.0–11.36.122, 11.40.0–11.40.71, 11.44.0–11.44.19, 11.46.0–11.46.19
Timeline
- 2026-09-08: disclosed: CVE-2026-77097 published; advisory CV_2026_08_1 issued
- 2026-09-08: patched: Resolved versions available: 11.36.123, 11.40.72, 11.44.20, 11.46.20 and higher