ZeroHour

CVE-2026-77098

Unauthenticated SQL Injection in Private Metrics Server

CVSS 4.0
8.8 high
EPSS
<1%p13
Published
()
Modified
AI analysis

Private Metrics Server contains an SQL injection flaw (CWE-89) in a condition governing its database operations. The CVSS 4.0 vector (AV:N/AC:L/AT:N/PR:N/UI:N) indicates it is exploitable remotely over a network with low attack complexity and no privileges or user interaction required, i.e., by an unauthenticated attacker. A successful attacker gains high-impact access to confidential database contents (VC:H), with low integrity and availability impact, and the flaw does not propagate to other systems (SC:N/SI:N/SA:N). Organizations running Private Metrics Server are affected and must apply the vendor's resolved maintenance release, though no specific vulnerable or fixed version numbers are provided in the disclosure. The flaw is not yet known to be exploited: no public proof of concept, not listed in CISA KEV, and EPSS assigns a 0.2% 30-day exploitation probability (13th percentile).

What to do: Upgrade Private Metrics Server to the vendor's resolved maintenance release, checking the vendor advisory for the exact fixed version since none is named in this disclosure. Until patched, restrict network access to the server (firewall/allow-list, VPN, or reverse proxy) and review database and web-server logs for anomalous SQL queries or probing. Because the flaw is unauthenticated but not yet observed in the wild, prioritize patching any internet-facing instances first.

Affected
Private Metrics Server
Estimated exposure
unknown — no install-base, active-install, or internet-exposure figures are available for Private Metrics Server — The disclosure provides no vendor name, install counts, or scan-derived internet-exposure data, and the self-hosted nature of the product offers no reliable basis for an order-of-magnitude estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.

Vendors
commvault
Products
commvault
Weakness
CWE-89
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.