CVE-2026-9787
Received Received - Intake
Quest NetVault Backup NVBULogDaemon Command Injection

Publication date: 2026-06-25

Last updated on: 2026-06-25

Assigner: Zero Day Initiative

Description
Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBULogDaemon JSON-RPC messages. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-27625.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-25
Last Modified
2026-06-25
Generated
2026-06-25
AI Q&A
2026-06-25
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
quest netvault_backup From 2025-09-24 (exc) to 2026-06-24 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-9787 is a remote code execution vulnerability in the Quest NetVault Backup software, specifically in the NVBULogDaemon component. The flaw exists because the software does not properly validate user-supplied strings in JSON-RPC messages before using them in system calls.

This improper validation allows an attacker to bypass the authentication mechanism and execute arbitrary code with SYSTEM-level privileges on the affected system.

Impact Analysis

This vulnerability can have severe impacts because it allows remote attackers to execute arbitrary code with SYSTEM privileges on affected installations of Quest NetVault Backup.

  • Attackers can gain full control over the affected system.
  • They can bypass authentication mechanisms.
  • Potentially, attackers could manipulate backup data, disrupt backup operations, or use the compromised system as a foothold for further attacks.
Mitigation Strategies

To mitigate this vulnerability, you should apply the update released by Quest that addresses the CVE-2026-9787 flaw in the NVBULogDaemon component of Quest NetVault Backup.

Since the vulnerability allows remote code execution by bypassing authentication, it is critical to update the affected software as soon as possible to prevent exploitation.

Compliance Impact

The provided information does not specify how this vulnerability impacts compliance with common standards and regulations such as GDPR or HIPAA.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9787. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart