Junglewise Threat Intelligence

CVE-2026-77098: Commvault Private Metrics Server SQL injection

CVE-2026-77098 · Severity: critical · CVSS 9.8 · Published 2026-09-08

Vendors: Commvault.

Executive brief

Commvault's Private Metrics Server, a monitoring and data collection component used in enterprise backup and disaster recovery environments, contains an SQL injection vulnerability in its database query handling. An attacker exploiting this flaw could execute arbitrary SQL commands, potentially leading to unauthorized data access, data modification, or service disruption affecting business continuity operations.

Technical details

The vulnerability is a classic SQL injection flaw in the Private Metrics Server component affecting database operations. The attack vector is network-based, allowing remote attackers to inject malicious SQL commands through untrusted input. Commvault has issued patches for affected versions across multiple release branches (11.46, 11.44, 11.40, and 11.36), with fixes available in 11.46.20, 11.44.20, 11.40.72, and 11.36.123 respectively. The CVSS 8.8 score reflects high severity, indicating significant impact on confidentiality and integrity of the database.

Affected products

  • Commvault Private Metrics Server 11.46.0-11.46.19, 11.44.0-11.44.19, 11.40.0-11.40.71, 11.36.0-11.36.122

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: patched: Patches available: 11.46.20+, 11.44.20+, 11.40.72+, 11.36.123+

References