ZDI-CAN-27625: ZDI-26-376: Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-9787.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-27625?
ZDI-CAN-27625 has a CVSS score of 8.8, indicating a high severity risk.
How do I fix ZDI-CAN-27625?
To fix ZDI-CAN-27625, apply the latest security patches provided by Quest for NetVault Backup.
What type of vulnerability is ZDI-CAN-27625?
ZDI-CAN-27625 is a command injection vulnerability that allows remote code execution.
Who is affected by ZDI-CAN-27625?
Organizations using Quest NetVault Backup are affected by ZDI-CAN-27625.
Can ZDI-CAN-27625 be exploited without authentication?
While authentication is normally required, the existing authentication mechanism can be bypassed for ZDI-CAN-27625.