ZDI-CAN-27626: ZDI-26-375: Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-9786.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-27626?
ZDI-CAN-27626 has a CVSS score of 8.8, indicating high severity.
How do I fix ZDI-CAN-27626?
To fix ZDI-CAN-27626, ensure that the latest security updates for Quest NetVault Backup are applied.
What is the impact of ZDI-CAN-27626?
ZDI-CAN-27626 allows remote code execution, potentially enabling attackers to run arbitrary code.
Is authentication required to exploit ZDI-CAN-27626?
Yes, authentication is required to exploit ZDI-CAN-27626, but the authentication mechanism can be bypassed.
What systems are affected by ZDI-CAN-27626?
ZDI-CAN-27626 affects installations of Quest NetVault Backup.