Executive brief
Veeam Backup & Replication is a platform used by organizations to manage and store backups of their critical data. A security vulnerability in this software allows a user with basic network credentials to bypass security controls and modify or delete files within the backup storage area. This could lead to the loss of backup integrity, potentially preventing a company from recovering data after a ransomware attack or system failure.
Technical details
A missing authorization vulnerability (CWE-862) and protection mechanism failure (CWE-693) exists in Veeam Backup & Replication. An attacker with low-privileged domain user credentials can exploit this flaw over the network without user interaction. Successful exploitation allows the attacker to bypass existing security restrictions to read, modify, or delete arbitrary files stored on the Backup Repository. This poses a significant risk to backup integrity and availability. The issue is resolved in Veeam Backup & Replication version 12.3.2.4465.
Affected products
- Veeam Veeam Backup & Replication 12.0.0.1402 up to 12.3.2.4165, 13.0.0.496 up to 13.0.1.1071
Timeline
- 2026-03-12: disclosed
- 2026-03-12: advisory
- 2026-03-12: patched: Fixed in version 12.3.2.4465