Junglewise Threat Intelligence

CVE-2026-9787: Quest NetVault Backup command injection in NVBULogDaemon

CVE-2026-9787 · Severity: high · CVSS 8.8 · Published 2026-06-25

Technologies: Quest NetVault Backup. Vendors: Quest.

Executive brief

Quest NetVault Backup is an enterprise data protection solution used to back up and recover data across physical and virtual environments. A security flaw in its logging component allows a remote attacker to bypass authentication and execute commands with administrative (SYSTEM) privileges. This could lead to a total compromise of the backup server, potentially allowing attackers to delete backups, steal sensitive data, or deploy ransomware across the infrastructure.

Technical details

A command injection vulnerability exists within the NVBULogDaemon component of Quest NetVault Backup due to improper validation of user-supplied strings in JSON-RPC messages. While the vulnerable function technically requires authentication, the existing authentication mechanism can be bypassed, making the flaw reachable by unauthenticated remote attackers. The root cause is the lack of sanitization of input before it is passed to a system call. Successful exploitation allows for remote code execution in the security context of SYSTEM. Quest has addressed this issue in NetVault Backup version 14.0.2.

Affected products

  • Quest NetVault Backup Versions prior to 14.0.2

Timeline

  • 2025-09-24: disclosed: Vulnerability reported to vendor
  • 2026-06-24: patched: Quest released version 14.0.2 to address the issue
  • 2026-06-24: advisory: Coordinated public release of advisory

References

Related threats