CVE-2026-9780
Received Received - Intake
Quest NetVault Backup addclient3 XSS Authentication Bypass

Publication date: 2026-06-25

Last updated on: 2026-06-25

Assigner: Zero Day Initiative

Description
Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the addclient3 webpage. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-27666.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-25
Last Modified
2026-06-25
Generated
2026-06-25
AI Q&A
2026-06-25
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
quest netvault_backup to 2026-06-24 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-9780 is a vulnerability in Quest NetVault Backup software that allows remote attackers to bypass authentication.

The flaw exists in the addclient3 webpage due to insufficient validation of user-supplied data, which enables attackers to inject arbitrary scripts.

Exploitation requires user interaction, such as the target visiting a malicious page or opening a malicious file.

Attackers can leverage this vulnerability, possibly in combination with others, to execute arbitrary code with SYSTEM privileges.

Impact Analysis

This vulnerability can have severe impacts as it allows remote attackers to bypass authentication and potentially execute arbitrary code with SYSTEM privileges.

Successful exploitation could lead to full system compromise, unauthorized access to sensitive data, and disruption of backup services.

Because the attacker can gain SYSTEM-level code execution, they could control or manipulate the affected system extensively.

Mitigation Strategies

To mitigate the CVE-2026-9780 vulnerability, you should apply the update released by Quest for the NetVault Backup software that addresses this issue.

Since the vulnerability requires user interaction via the addclient3 webpage, limiting access to this page and educating users to avoid visiting untrusted pages or opening suspicious files can help reduce risk.

Compliance Impact

The vulnerability allows remote attackers to bypass authentication and potentially execute arbitrary code with SYSTEM privileges on affected Quest NetVault Backup installations.

Such unauthorized access and potential control over backup systems could lead to exposure or manipulation of sensitive data, which may impact compliance with data protection regulations like GDPR and HIPAA that require strict access controls and data integrity.

However, the provided information does not explicitly discuss the direct impact on compliance with these standards.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9780. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart