CyberICT

CVE-2026-77098

Commvault · Published September 8, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.

Affected Products

  • Commvault < 11.36.123
  • Commvault < 11.40.72
  • Commvault < 11.44.20
  • Commvault < 11.46.20

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H