Critical SQL Injection Vulnerability in Quest NetVault Backup Disclosed

Critical SQL Injection Vulnerability in Quest NetVault Backup Disclosed

First seen 26 Jun 2026, 06:39 UTC Mondoowww.zerodayinitiative.comwww.cve.org 92% similarity 72.0
Share:

Article Content

Browse articles
ThreatCluster

A critical vulnerability, CVE-2026-9783, has been identified in Quest NetVault Backup, allowing remote attackers to execute arbitrary code. This SQL injection flaw is found in the processing of NVBURemovableMedia JSON-RPC messages, where inadequate validation of user-supplied strings leads to SQL query manipulation. Although authentication is required for exploitation, it can be bypassed, increasing the risk of unauthorized access. The vulnerability affects installations of Quest NetVault Backup and can execute code in the context of NETWORK SERVICE. Quest has released an update to address this issue. The CVE was published on June 24, 2026, and security professionals are advised to apply the patch immediately.

Key Points: • CVE-2026-9783 allows remote code execution via SQL injection in Quest NetVault Backup. • Authentication can be bypassed, increasing the vulnerability's risk level. • Quest has issued a patch to mitigate the vulnerability.

ThreatCluster AI

Timeline

2026-06-24
CVE-2026-9783 published
The vulnerability in Quest NetVault Backup was officially published, detailing the SQL injection flaw.
Mondoo
2026-06-25
Vulnerability details reported
Mondoo reported on the SQL injection vulnerability, emphasizing its potential for remote code execution.
Mondoo
2026-06-26
Advisory issued by Zero Day Initiative
The Zero Day Initiative confirmed the vulnerability details and noted that Quest has released a patch.
www.zerodayinitiative.com

Community

Browse all →