CVE-2026-77098
Unauthenticated SQL Injection in Private Metrics Server
Private Metrics Server contains an SQL injection flaw (CWE-89) in a condition governing its database operations. The CVSS 4.0 vector (AV:N/AC:L/AT:N/PR:N/UI:N) indicates it is exploitable remotely over a network with low attack complexity and no privileges or user interaction required, i.e., by an unauthenticated attacker. A successful attacker gains high-impact access to confidential database contents (VC:H), with low integrity and availability impact, and the flaw does not propagate to other systems (SC:N/SI:N/SA:N). Organizations running Private Metrics Server are affected and must apply the vendor's resolved maintenance release, though no specific vulnerable or fixed version numbers are provided in the disclosure. The flaw is not yet known to be exploited: no public proof of concept, not listed in CISA KEV, and EPSS assigns a 0.2% 30-day exploitation probability (13th percentile).
What to do: Upgrade Private Metrics Server to the vendor's resolved maintenance release, checking the vendor advisory for the exact fixed version since none is named in this disclosure. Until patched, restrict network access to the server (firewall/allow-list, VPN, or reverse proxy) and review database and web-server logs for anomalous SQL queries or probing. Because the flaw is unauthenticated but not yet observed in the wild, prioritize patching any internet-facing instances first.
| Private Metrics Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
- Vendors
- commvault
- Products
- commvault
- Weakness
- CWE-89
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.