Vulnerability Intelligence Report
Private Metrics Server SQL Injection
CVE-2026-77098
Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-89 ↗CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Commvault | Commvault Cloud | 11.46.0 <= 11.46.19 (affected), 11.44.0 <= 11.44.19 (affected), 11.40.0 <= 11.40.71 (affected), 11.36.0 <= 11.36.122 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Commvault Systems Inc. · Vendor · USA |
| Reserved | 2026-08-20T10:56:58 |
| Published | 2026-09-08T12:12:53 |
| Last Updated | 2026-09-08T13:27:30 |
Community Chatter & Buzz