DIRAS TAKE
Urgent: this is an unauthenticated, network-accessible SQL injection (no login required), which can let attackers access or alter backend data; immediately reduce exposure and prepare to apply vendor fixes or mitigations when released.
What is CVE-2026-77098?
Remote attackers can execute SQL injection against Commvault Cloud's Private Metrics Server and potentially read or manipulate its database; see CVE-2026-77098. The report lists multiple affected 11.x release ranges: 11.46.0–11.46.19, 11.44.0–11.44.19, 11.40.0–11.40.71, and 11.36.0–11.36.122. According to the CVSS vector, exploitation can be performed over the network without authentication or user interaction, allowing high-impact confidentiality, integrity, and availability consequences. The weakness is classified as CWE-89 (SQL Injection).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Commvault Commvault Cloud are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 11.x | 11.46.0 – 11.46.19 | |
| 11.x | 11.44.0 – 11.44.19 | |
| 11.x | 11.40.0 – 11.40.71 | |
| 11.x | 11.36.0 – 11.36.122 |
Is CVE-2026-77098 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-77098
- Isolate or block access to the Private Metrics Server from untrusted networks and the internet.
- Apply any vendor guidance and monitor Commvault security advisories for an official patch or maintenance release.
- Enable and review database and application logs for suspicious queries or anomalies related to the Private Metrics Server.
- Restrict database credentials and rotate them, and implement network-level controls such as allowlists for administrative access.
Frequently asked questions
Is CVE-2026-77098 being actively exploited?
There are no public reports of active exploitation of CVE-2026-77098 as of 2026-09-30; it is not listed in CISA's KEV catalog and no public exploit code has been reported.
Which Commvault Cloud versions are affected by CVE-2026-77098?
Commvault Cloud's Private Metrics Server is reported affected in these 11.x ranges: 11.46.0–11.46.19, 11.44.0–11.44.19, 11.40.0–11.40.71, and 11.36.0–11.36.122.
Is there a patch for CVE-2026-77098?
No fixed releases are listed in the provided data; follow Commvault advisories for a maintenance release and apply vendor instructions when a patch is published.
Does CVE-2026-77098 require authentication?
No; the vulnerability is described as exploitable over the network without authentication, meaning attackers do not need valid credentials to attempt SQL injection.
References
- nvd.nist.gov/vuln/detail/CVE-2026-77098
- cve.org/CVERecord?id=CVE-2026-77098
- documentation.commvault.com/securityadvisories/CV_2026_08_2.html
- All Commvault CVEs on CVE Radar
- CVEs published in September 2026