Junglewise Threat Intelligence

CVE-2026-9781: Quest NetVault Backup SQL injection in NVBURASDevice

CVE-2026-9781 · Severity: high · CVSS 8.8 · Published 2026-06-25

Technologies: Quest NetVault Backup. Vendors: Quest.

Executive brief

Quest NetVault Backup is a data protection solution used to back up and restore enterprise data across physical and virtual environments. A security vulnerability in the NVBURASDevice component allows a remote attacker to bypass authentication and execute unauthorized commands on the server. This could lead to a total compromise of the backup system, potentially allowing attackers to access, modify, or delete sensitive backup data and disrupt business continuity.

Technical details

A SQL injection vulnerability exists within the NVBURASDevice component of Quest NetVault Backup during the processing of JSON-RPC messages. The root cause is a failure to properly validate user-supplied strings before they are used to construct SQL queries. While the vulnerability technically requires authentication, the existing authentication mechanism can be bypassed, making it accessible to remote attackers. Successful exploitation allows for remote code execution in the security context of the NETWORK SERVICE account. The issue is addressed in version 14.0.2.

Affected products

  • Quest NetVault Backup 14.0.0.19

Timeline

  • 2025-09-24: disclosed: Vulnerability reported to vendor via ZDI
  • 2026-06-24: patched: Coordinated public release of advisory and update
  • 2026-06-25: advisory: NVD publication date

References

Related threats