Critical SQL Injection Vulnerability in Quest NetVault Backup Disclosed
Article Content
- •CVE-2026-9783 allows remote code execution via SQL injection in Quest NetVault Backup.
- •Authentication can be bypassed, increasing the vulnerability's risk level.
- •Quest has issued a patch to mitigate the vulnerability.
A critical vulnerability, CVE-2026-9783, has been identified in Quest NetVault Backup, allowing remote attackers to execute arbitrary code. This SQL injection flaw is found in the processing of NVBURemovableMedia JSON-RPC messages, where inadequate validation of user-supplied strings leads to SQL query manipulation. Although authentication is required for exploitation, it can be bypassed, increasing the risk of unauthorized access. The vulnerability affects installations of Quest NetVault Backup and can execute code in the context of NETWORK SERVICE. Quest has released an update to address this issue. The CVE was published on June 24, 2026, and security professionals are advised to apply the patch immediately.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Quest and CVE-2026-9783 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…