Executive brief
Quest NetVault Backup is a data protection solution used to back up and recover enterprise data across physical and virtual environments. A security flaw in how the software handles database queries allows a remote attacker to bypass security checks and execute unauthorized commands. This could lead to a complete takeover of the backup server, potentially resulting in the loss or theft of sensitive corporate data and backups.
Technical details
An SQL injection vulnerability exists within the NVBULibraryPort component of Quest NetVault Backup during the processing of JSON-RPC messages. The root cause is a failure to properly validate user-supplied strings before they are used to construct SQL queries. While the vulnerability technically requires authentication, the advisory notes that the existing authentication mechanism can be bypassed. A remote attacker can exploit this flaw to execute arbitrary code in the context of the NETWORK SERVICE account. The issue was addressed in version 14.0.2.
Affected products
- Quest NetVault Backup 14.0.0.19
Timeline
- 2025-09-24: disclosed: Vulnerability reported to vendor via ZDI
- 2026-06-24: patched: Vendor released version 14.0.2 to address the issue
- 2026-06-24: advisory: Coordinated public release of advisory ZDI-26-373