Junglewise Threat Intelligence

CVE-2026-9786: Quest NetVault Backup SQL injection in NVBUDashboard

CVE-2026-9786 · Severity: high · CVSS 8.8 · Published 2026-06-25

Technologies: Quest NetVault Backup. Vendors: Quest.

Executive brief

Quest NetVault Backup is a data protection solution used to back up and recover data across physical and virtual environments. A security vulnerability in its dashboard component allows remote attackers to bypass authentication and execute unauthorized commands. This could lead to a total compromise of the backup server, potentially allowing attackers to access, modify, or delete sensitive backup data and disrupt business continuity.

Technical details

A SQL injection vulnerability exists within the NVBUDashboard component of Quest NetVault Backup during the processing of JSON-RPC messages. The root cause is a failure to properly validate user-supplied strings before they are used to construct SQL queries. While the vulnerability technically requires authentication (PR:L), the advisory notes that the existing authentication mechanism can be bypassed, effectively making this reachable by unauthenticated remote attackers. Successful exploitation allows for remote code execution in the security context of the NETWORK SERVICE account. The issue is addressed in version 14.0.2.

Affected products

  • Quest NetVault Backup 14.0.0.19

Timeline

  • 2025-09-24: disclosed: Vulnerability reported to vendor
  • 2026-06-24: patched: Coordinated public release of advisory and fix in version 14.0.2
  • 2026-06-25: advisory: NVD publication date

References

Related threats