Executive brief
Quest NetVault Backup is a data protection solution used to back up and recover enterprise data across physical and virtual environments. A security vulnerability in the software allows a remote attacker to bypass authentication and execute unauthorized commands on the server. This could lead to a total compromise of the backup system, potentially allowing attackers to access sensitive customer data, delete backups, or disrupt business operations.
Technical details
A SQL injection vulnerability exists within the NVBUDeviceDrive component of Quest NetVault Backup during the processing of JSON-RPC messages. The flaw stems from insufficient validation of user-supplied strings before they are used to construct SQL queries. While the exploit technically requires authentication, the advisory notes that the existing authentication mechanism can be bypassed. A remote, unauthenticated attacker can leverage this to execute arbitrary code in the security context of the NETWORK SERVICE account. Quest has addressed this issue in NetVault Backup version 14.0.2.
Affected products
- Quest NetVault Backup Prior to 14.0.2
Timeline
- 2025-09-24: disclosed: Vulnerability reported to vendor
- 2026-06-24: patched: Coordinated public release of advisory and fix in version 14.0.2
- 2026-06-25: advisory: NVD publication date