CVE-2026-9784: Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability
Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
The specific flaw exists within the processing of NVBULibraryPort JSON-RPC messages. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-27631.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9784?
CVE-2026-9784 has a severity score of 8.8, classifying it as high risk.
What type of vulnerability is CVE-2026-9784?
CVE-2026-9784 is classified as an SQL Injection vulnerability that can lead to remote code execution.
How can CVE-2026-9784 be exploited?
CVE-2026-9784 can be exploited by remote attackers who have authenticated access to execute arbitrary code.
What software is affected by CVE-2026-9784?
CVE-2026-9784 affects installations of Quest NetVault Backup.
What is the impact of CVE-2026-9784 on affected systems?
The impact of CVE-2026-9784 includes potential unauthorized access and control over affected systems due to remote code execution capabilities.