Executive brief
Quest NetVault Backup is a data protection solution used to back up and recover enterprise data across physical and virtual environments. A security vulnerability in its dashboard component allows a remote attacker to bypass authentication and execute arbitrary commands on the server. This could lead to a total compromise of the backup system, potentially allowing attackers to access, modify, or delete sensitive backup data and disrupt business continuity.
Technical details
A SQL injection vulnerability exists within the NVBUDashboard component of Quest NetVault Backup during the processing of JSON-RPC messages. The root cause is a failure to properly validate user-supplied strings before they are used to construct SQL queries. While the vulnerability technically requires authentication (PR:L), the advisory notes that the existing authentication mechanism can be bypassed, effectively allowing unauthenticated remote attackers to exploit the flaw. Successful exploitation allows for arbitrary code execution in the security context of the NETWORK SERVICE account. The issue was addressed in version 14.0.2.
Affected products
- Quest NetVault Backup 14.0.0.19
Timeline
- 2025-09-24: disclosed: Vulnerability reported to vendor via ZDI
- 2026-06-24: patched: Quest released version 14.0.2 to address the issue
- 2026-06-24: advisory: Coordinated public release of advisory