Skip to content
Critical SQL Injection Vulnerability in Quest NetVault Backup Disclosed

Critical SQL Injection Vulnerability in Quest NetVault Backup Disclosed

First seen 26 Jun 2026, 06:39 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 27, 2026 at 05:43 UTC

A critical vulnerability, CVE-2026-9783, has been identified in Quest NetVault Backup, allowing remote attackers to execute arbitrary code. This SQL injection flaw is found in the processing of NVBURemovableMedia JSON-RPC messages, where inadequate validation of user-supplied strings leads to SQL query manipulation. Although authentication is required for exploitation, it can be bypassed, increasing the risk of unauthorized access. The vulnerability affects installations of Quest NetVault Backup and can execute code in the context of NETWORK SERVICE. Quest has released an update to address this issue. The CVE was published on June 24, 2026, and security professionals are advised to apply the patch immediately.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 106d ago How this analysis works

Timeline

2026-06-24
CVE-2026-9783 published
The vulnerability in Quest NetVault Backup was officially published, detailing the SQL injection flaw.
Mondoo
2026-06-25
Vulnerability details reported
Mondoo reported on the SQL injection vulnerability, emphasizing its potential for remote code execution.
Mondoo
2026-06-26
Advisory issued by Zero Day Initiative
The Zero Day Initiative confirmed the vulnerability details and noted that Quest has released a patch.
www.zerodayinitiative.com

More articles in this cluster (3)

Following this threat?

Track Quest and CVE-2026-9783 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed