Junglewise Threat Intelligence

CVE-2026-7569: Quest NetVault Backup XSS authentication bypass in viewclient

CVE-2026-7569 · Severity: high · CVSS 8.8 · Published 2026-06-25

Technologies: Quest NetVault Backup. Vendors: Quest.

Executive brief

Quest NetVault Backup is a data protection solution used to back up and recover enterprise data across physical and virtual environments. A security flaw in its web interface allows a remote attacker to bypass authentication if a legitimate user is tricked into visiting a malicious link. This could allow an attacker to gain unauthorized access to the backup system and potentially execute commands with high-level system privileges, risking data loss or full system compromise.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the 'viewclient' webpage of Quest NetVault Backup due to insufficient validation of user-supplied data. A remote, unauthenticated attacker can exploit this by enticing a user to visit a specially crafted URL or open a malicious file, leading to the execution of arbitrary script code in the victim's browser session. This script execution can be leveraged to bypass authentication mechanisms. When combined with other vulnerabilities, this flaw allows for arbitrary code execution with SYSTEM privileges. The issue is addressed in NetVault version 14.0.2.

Affected products

  • Quest NetVault Backup 14.0.1.7

Timeline

  • 2025-10-03: disclosed: Vulnerability reported to vendor
  • 2026-06-24: patched: Coordinated public release of advisory and update
  • 2026-06-25: advisory: NVD publication date

References

Related threats