Junglewise Threat Intelligence

CVE-2026-9783: Quest NetVault Backup SQL injection in NVBURemovableMedia

CVE-2026-9783 · Severity: high · CVSS 8.8 · Published 2026-06-25

Technologies: Quest NetVault Backup. Vendors: Quest.

Executive brief

Quest NetVault Backup is a data protection solution used to back up and restore enterprise data across physical and virtual environments. A security flaw in its removable media management component allows a remote attacker to bypass authentication and execute unauthorized commands on the server. This could lead to a total compromise of the backup system, potentially resulting in the loss, theft, or encryption of critical business data.

Technical details

A SQL injection vulnerability exists within the NVBURemovableMedia component of Quest NetVault Backup due to insufficient validation of user-supplied strings in JSON-RPC messages. While the vulnerable function technically requires authentication, the existing authentication mechanism can be bypassed, making the flaw reachable by unauthenticated remote attackers. By injecting malicious SQL commands, an attacker can achieve remote code execution in the security context of the NETWORK SERVICE account. The vulnerability was addressed in Quest NetVault Backup version 14.0.2.

Affected products

  • Quest NetVault Backup 14.0.0.19 and earlier

Timeline

  • 2025-09-24: disclosed: Vulnerability reported to vendor via ZDI
  • 2026-06-24: advisory: ZDI advisory published
  • 2026-06-24: patched: Quest released version 14.0.2 to address the issue
  • 2026-06-25: other: CVE published to NVD

References

Related threats