ZDI-26-374: Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-9785.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-374?
The vulnerability ZDI-26-374 has a CVSS rating of 8.8, indicating a high severity risk.
How do I fix ZDI-26-374?
To remediate ZDI-26-374, ensure you apply the latest security update provided by Quest for NetVault Backup.
What type of vulnerability is ZDI-26-374?
ZDI-26-374 is a SQL Injection vulnerability that can lead to remote code execution.
Does ZDI-26-374 require authentication?
Yes, ZDI-26-374 requires authentication, but the bypass of the existing authentication mechanism is possible.
What can attackers do with ZDI-26-374?
Attackers exploiting ZDI-26-374 can execute arbitrary code on affected installations of Quest NetVault Backup.