ZDI-26-369: Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-9780.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
For Quest NetVault Backup installations, implement network- and gateway-level controls to block access to known or suspected malicious websites and exploit pages (for example via web proxy, web filtering, or WAF). Also block, quarantine, or sandbox incoming files from untrusted sources at the email gateway or file-transfer layer and enable endpoint attachment scanning to prevent users from opening potentially malicious files (exploitation requires visiting a malicious page or opening a malicious file).
- Operational
Notify users and administrators of Quest NetVault Backup to avoid visiting untrusted websites and to not open files from unknown or untrusted sources until a vendor patch is available. If files related to NetVault Backup must be opened, scan and sandbox them first.
Event History
Frequently Asked Questions
What is the severity of ZDI-26-369?
ZDI-26-369 has a CVSS rating of 8.8, indicating a high severity risk.
How do I fix ZDI-26-369?
To fix ZDI-26-369, ensure that you update your Quest NetVault Backup software to the latest version provided by the vendor.
What type of attack is possible with ZDI-26-369?
ZDI-26-369 allows remote attackers to execute a Cross-Site Scripting (XSS) attack that can bypass authentication.
Is user interaction required to exploit ZDI-26-369?
Yes, user interaction is required, as the target must visit a malicious page or open a malicious file to exploit ZDI-26-369.
Which software is affected by ZDI-26-369?
ZDI-26-369 affects installations of Quest NetVault Backup.