CVE-2026-77098: sql injection in Commvault Commvault Cloud

Remote attackers can execute SQL injection against Commvault Cloud's Private Metrics Server and potentially read or manipulate its database; see CVE-2026-77098. The report lists multiple affected 11.x release ranges: 11.46.0–11.46.19, 11.44.0–11.44.19, 11.40.0–11.40.71, and 11.36.0–11.36.122. According to the CVSS vector, exploitation can be performed over the network without authentication or user interaction, allowing high-impact confidentiality, integrity, and availability consequences.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00468
CWE
CWE-89
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this is an unauthenticated, network-accessible SQL injection (no login required), which can let attackers access or alter backend data; immediately reduce exposure and prepare to apply vendor fixes or mitigations when released.

What is CVE-2026-77098?

Remote attackers can execute SQL injection against Commvault Cloud's Private Metrics Server and potentially read or manipulate its database; see CVE-2026-77098. The report lists multiple affected 11.x release ranges: 11.46.0–11.46.19, 11.44.0–11.44.19, 11.40.0–11.40.71, and 11.36.0–11.36.122. According to the CVSS vector, exploitation can be performed over the network without authentication or user interaction, allowing high-impact confidentiality, integrity, and availability consequences. The weakness is classified as CWE-89 (SQL Injection).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Commvault Commvault Cloud are affected?

BRANCHAFFECTEDFIXED
11.x11.46.0 – 11.46.19
11.x11.44.0 – 11.44.19
11.x11.40.0 – 11.40.71
11.x11.36.0 – 11.36.122

Is CVE-2026-77098 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-77098

  1. Isolate or block access to the Private Metrics Server from untrusted networks and the internet.
  2. Apply any vendor guidance and monitor Commvault security advisories for an official patch or maintenance release.
  3. Enable and review database and application logs for suspicious queries or anomalies related to the Private Metrics Server.
  4. Restrict database credentials and rotate them, and implement network-level controls such as allowlists for administrative access.

Frequently asked questions

Is CVE-2026-77098 being actively exploited?

There are no public reports of active exploitation of CVE-2026-77098 as of 2026-09-30; it is not listed in CISA's KEV catalog and no public exploit code has been reported.

Which Commvault Cloud versions are affected by CVE-2026-77098?

Commvault Cloud's Private Metrics Server is reported affected in these 11.x ranges: 11.46.0–11.46.19, 11.44.0–11.44.19, 11.40.0–11.40.71, and 11.36.0–11.36.122.

Is there a patch for CVE-2026-77098?

No fixed releases are listed in the provided data; follow Commvault advisories for a maintenance release and apply vendor instructions when a patch is published.

Does CVE-2026-77098 require authentication?

No; the vulnerability is described as exploitable over the network without authentication, meaning attackers do not need valid credentials to attempt SQL injection.

References