ZDI-CAN-27666: ZDI-26-369: Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-9780.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-27666?
ZDI-CAN-27666 has a CVSS rating of 8.8, indicating a high severity risk.
How do I fix ZDI-CAN-27666?
To fix ZDI-CAN-27666, update Quest NetVault Backup to the latest version provided by Quest Software.
What type of vulnerability is ZDI-CAN-27666?
ZDI-CAN-27666 is a Cross-Site Scripting Authentication Bypass vulnerability.
Who is affected by ZDI-CAN-27666?
ZDI-CAN-27666 affects installations of Quest NetVault Backup that have not been patched.
Can ZDI-CAN-27666 be exploited remotely?
Yes, ZDI-CAN-27666 can be exploited remotely, but user interaction is required to successfully bypass authentication.