ZeroHour

CVE-2026-77097

Unauthenticated Metrics Upload Flaw Enables DoS in Private Metrics Server

CVSS 4.0
8.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

Private Metrics Server contains a missing-authentication condition (CWE-306) in its metrics upload functionality, meaning the endpoint accepts requests without verifying the caller's identity. An attacker with network access to the service can submit or manipulate metrics uploads without any credentials, producing a low integrity impact, and can disrupt the service, with the CVSS 4.0 vector indicating a high availability impact (denial of service); there is no confidentiality impact, so this is not a data-theft issue. The vulnerability is triggered remotely over the network with no privileges or user interaction required (AV:N/PR:N/UI:N). Organizations running affected releases of Private Metrics Server are affected, and exposure is highest where the metrics upload interface is reachable from untrusted networks. As of now, there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days.

What to do: Update Private Metrics Server to the resolved maintenance release referenced in the vendor advisory; no specific fixed version number is given in the available data, so consult the vendor's advisory for the exact release. Until patched, restrict network access to the metrics upload interface (firewall rules, ACLs, or authentication enforcement at a reverse proxy) and monitor for unexpected metric uploads or service availability issues.

Affected
Private Metrics Server
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.

Vendors
commvault
Products
commvault
Weakness
CWE-306
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.