SQL injection in Commvault - CVE-2026-77098
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information, modify data, and cause a denial of service.
The vulnerability exists due to SQL injection in Private Metrics Server when processing database operations. A remote attacker can submit crafted SQL input to disclose sensitive information, modify data, and cause a denial of service.