CVE Tools

Description

Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBULogDaemon JSON-RPC messages. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-27625.

In plain language

AI Worth attention

This NetVault Backup bug lets an attacker send a special remote request that can run commands as the Windows SYSTEM account; it’s a serious risk for businesses that expose NetVault/its log service to the network, but the exact affected setup and fix details aren’t confirmed yet.

Executive summary

CVE-2026-9787 is a command-injection remote code execution flaw in Quest NetVault Backup’s NVBULogDaemon JSON-RPC message processing, allowing attackers to execute arbitrary code with SYSTEM privileges through improper input validation; the findings do not confirm whether the attacker must be authenticated (or whether authentication can be bypassed).

If affected, business impact
Full system compromiseBackup system takeoverRansomware riskService disruption

What to do now

  1. Check whether you run Quest NetVault Backup and whether the NVBULogDaemon service is installed and actively running on any server.
  2. Verify whether NVBULogDaemon’s network interface (the JSON-RPC endpoint) is reachable from other machines or the internet (not just localhost).
  3. Look for any recent security advisories, hotfixes, or updated NetVault Backup downloads specifically referencing CVE-2026-9787; if none exist, open a ticket with Quest support.
  4. If external reachability exists, restrict it immediately by limiting network access (firewall/VPN/IP allow-list) to only the required internal administration hosts.
  5. Confirm your backup servers and related endpoints are patched up to the latest available NetVault Backup version from Quest, and document the current version for follow-up once a fix is published.
May need vendor / contractor work

CVSS Vector Breakdown

AV:NAC:LPR:LUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 1 more affected products View all →

Exploitability

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Execution
View detailed technique mapping

References

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-9787 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows