ZDI-26-375: Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability
Published Jun 24, 2026
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-9786.
Affected Software
1 affected component
Quest NetVault Backup
Event History
Jun 24, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Advisory Published
via ZDI·11:45 PM
Data Sourced
via ZDI·11:45 PM
Affected Software
Frequently Asked Questions
1
What is the severity of ZDI-26-375?
The severity of ZDI-26-375 is rated at 8.8 on the CVSS scale.
2
How do I fix ZDI-26-375?
To fix ZDI-26-375, ensure you apply the latest security patches from Quest for NetVault Backup.
3
What is the nature of the vulnerability identified by ZDI-26-375?
ZDI-26-375 is a SQL Injection vulnerability that allows remote code execution on affected systems.
4
Is authentication required to exploit ZDI-26-375?
Yes, authentication is required to exploit ZDI-26-375, but the authentication mechanism can be bypassed.
5
Which software is affected by ZDI-26-375?
ZDI-26-375 affects installations of Quest NetVault Backup.