Junglewise Threat Intelligence

CVE-2022-26501: Veeam Backup & Replication Remote Code Execution Vulnerability

CVE-2022-26501 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-12-13

Technologies: Nakivo Backup, Nakivo Replication, Veeam Backup & Replication. Vendors: Nakivo, Veeam.

Executive brief

The Veeam Distribution Service in Veeam Backup & Replication allows unauthenticated users to access internal API functions due to incorrect access control. A remote attacker can exploit this to send input to the internal API, potentially leading to the upload and execution of malicious code.

Affected products

  • Veeam Backup & Replication 10.x, 11.x

Timeline

  • 2022-12-13: disclosed
  • 2022-12-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats