Executive brief
Veeam Backup & Replication is a data protection solution used to back up, restore, and replicate virtual and physical machines. A critical vulnerability allows a user with basic domain credentials to execute malicious code on the backup server. This could lead to a total compromise of the backup infrastructure, potentially allowing an attacker to delete backups, steal sensitive data, or deploy ransomware across the environment.
Technical details
A remote code execution (RCE) vulnerability exists in Veeam Backup & Replication due to improper control of code generation (CWE-94). The flaw allows an authenticated domain user to execute arbitrary commands on the Backup Server with high privileges. The attack vector is over the network and requires low-privileged authentication but no user interaction. Successful exploitation results in a full system compromise (Confidentiality, Integrity, and Availability impact) and allows the attacker to escape the initial security scope. The issue is resolved in Veeam Backup & Replication version 13.0.1.2067.
Affected products
- Veeam Veeam Backup & Replication 13.0.0.496 up to 13.0.1.1071
Timeline
- 2026-03-12: disclosed
- 2026-03-12: advisory
- 2026-03-12: patched: Fixed in version 13.0.1.2067