Junglewise Threat Intelligence

CVE-2026-9782: Quest NetVault Backup SQL injection in NVBUDeviceDrive

CVE-2026-9782 · Severity: high · CVSS 8.8 · Published 2026-06-25

Technologies: Quest NetVault Backup. Vendors: Quest.

Executive brief

Quest NetVault Backup is a data protection solution used to back up and recover enterprise data across physical and virtual environments. A security vulnerability in the software allows a remote attacker to bypass authentication and execute unauthorized commands on the server. This could lead to a total compromise of the backup system, potentially allowing attackers to access sensitive customer data, delete backups, or disrupt business operations.

Technical details

A SQL injection vulnerability exists within the NVBUDeviceDrive component of Quest NetVault Backup during the processing of JSON-RPC messages. The flaw stems from insufficient validation of user-supplied strings before they are used to construct SQL queries. While the exploit technically requires authentication, the advisory notes that the existing authentication mechanism can be bypassed. A remote, unauthenticated attacker can leverage this to execute arbitrary code in the security context of the NETWORK SERVICE account. Quest has addressed this issue in NetVault Backup version 14.0.2.

Affected products

  • Quest NetVault Backup Prior to 14.0.2

Timeline

  • 2025-09-24: disclosed: Vulnerability reported to vendor
  • 2026-06-24: patched: Coordinated public release of advisory and fix in version 14.0.2
  • 2026-06-25: advisory: NVD publication date

References

Related threats